Command Injection Vulnerability in Netis N3Mv2 Hardware
CVE-2023-43891
9.8CRITICAL
What is CVE-2023-43891?
The Netis N3Mv2 device version V1.0.1.865 exhibits a command injection vulnerability within its functionality for changing usernames and passwords. An attacker can exploit this vulnerability by sending a specially crafted payload, compromising the integrity of the device and potentially enabling unauthorized access. This poses a significant security risk, emphasizing the need for timely updates and vigilant monitoring of device configurations.
News Articles

CVE-2023-43891 Netis N3Mv2-V1.0.1.865 exists to contain a comm...
Netis N3Mv2-V1.0.1.865 exists to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability is exploited via a