Command Injection Vulnerability in COMFAST CF-XR11 by COMFAST
CVE-2023-38866
9.8CRITICAL
What is CVE-2023-38866?
The COMFAST CF-XR11 V2.7.2 contains a command injection vulnerability that can be exploited by sending specially crafted POST requests to the web management interface. This vulnerability arises from inadequate input validation in the 'interface' and 'display_name' parameters, allowing attackers to execute arbitrary commands on the device. Such exploitation could lead to unauthorized access or manipulation of the device's configurations, posing substantial security risks to users.
