CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2023-39367

CVSS 9.1v3.1pub. 2024-04-17upd. 2025-11-04

An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

🤖 AI Analysis
How it works

The vulnerability results from improper input validation in the mac2name function available through the web interface. An attacker can send a specially crafted HTTP request containing malicious data that is passed directly to the system shell without proper sanitization. The exploit requires authentication to the device's web interface, but once obtained, it is possible to execute arbitrary commands with the privileges of the process handling the interface.

Impact

An authenticated attacker can execute arbitrary system commands on the device, which may lead to complete device takeover, disclosure of sensitive data, modification of configuration, and system availability disruption.

Mitigation & patch

Security patches available from the manufacturer should be applied according to the references — detailed information is available in the official Peplink security advisory at the address indicated in the manufacturer's references

Who is affected

Peplink Smart Reader firmware version 1.2.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
  • Peplink Smart Reader

    HW
    Peplink
    all versions
  • Peplink Smart Reader Firmware

    OS
    Peplink
    1.2.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2023-45744HIGH8.3same product

A data integrity vulnerability exists in the web interface /cgi-bin/upload_config.cgi functionality of Peplink...

CVE-2023-40146MEDIUM6.8same product

A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in...

CVE-2023-43491MEDIUM5.3same product

An information disclosure vulnerability exists in the web interface /cgi-bin/debug_dump.cgi functionality of P...

CVE-2023-45209MEDIUM5.3same product

An information disclosure vulnerability exists in the web interface /cgi-bin/download_config.cgi functionality...

CVE-2017-8835CRITICAL9.8PL ✓same vendor

SQL Injection w urządzeniach Peplink Balance poprzez ciasteczko bauth