OS Command Injection Vulnerability in Peplink Surf SOHO Hardware
CVE-2023-35194
7.2HIGH
What is CVE-2023-35194?
The Peplink Surf SOHO HW1 suffers from an OS command injection vulnerability that can be exploited via the api.cgi cmd.mvpn.x509.write functionality. By sending a specially crafted HTTP request, an authenticated user can trigger command execution on the device. This flaw arises from the insecure handling of input for the system call located in the /web/MANGA/cgi-bin/api.cgi file within firmware version 6.3.5.
Affected Version(s)
Surf SOHO HW1 v6.3.5 (in QEMU)
References
EPSS Score
5% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Discovered by Matt Wiseman of Cisco Talos.
