Post-Auth Command Injection in Telstra Smart Modem Gen 2 (Arcadyan LH1000)
CVE-2023-43477

6.8MEDIUM

Key Information:

Vendor

Telstra

Vendor
CVE Published:
20 September 2023

What is CVE-2023-43477?

The ping_from parameter of ping_tracerte.cgi in the web UI of Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, was not properly sanitized before being used in a system call, which could allow an authenticated attacker to achieve command injection as root on the device. 

Affected Version(s)

Smart Modem Gen 2 (Arcadyan LH1000) 0 < 0.18.15r

References

EPSS Score

20% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.