Unknown
CVE-2023-38902
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2023-38902
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless access points v.AP_3.0(1)B11P219, and NBC series wireless controllers v.AC_3.0(1)B11P219 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /cgi-bin/luci/api/cmd via the remoteIp field.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- rg-eap101 firmware 3.0(1)b11p219,
- rg-eap101 v2 firmware 3.0(1)b11p219,
- rg-eap102 firmware 3.0(1)b11p219,
- rg-eap102 v2 firmware 3.0(1)b11p219,
- rg-eap102(f) firmware 3.0(1)b11p219,
- rg-eap162(g) firmware 3.0(1)b11p219,
- rg-eap201 firmware 3.0(1)b11p219,
- rg-eap202 firmware 3.0(1)b11p219,
- rg-eap212(f) firmware 3.0(1)b11p219,
- rg-eap212(g) firmware 3.0(1)b11p219,
- rg-eap262(g) firmware 3.0(1)b11p219,
- rg-eap602 firmware 3.0(1)b11p219,
- rg-eap662(g) firmware 3.0(1)b11p219,
- rg-eg105g v2 firmware 3.0(1)b11p219,
- rg-eg105g-e firmware 3.0(1)b11p219,
- rg-eg105g-pe firmware 3.0(1)b11p219,
- rg-eg210g-e firmware 3.0(1)b11p219,
- rg-eg210g-p firmware 3.0(1)b11p219,
- rg-eg210g-pe firmware 3.0(1)b11p219,
- rg-ew1200 firmware 3.0(1)b11p219,
- rg-ew1200g pro firmware 3.0(1)b11p219,
- rg-ew1200r firmware 3.0(1)b11p219,
- rg-ew1300g firmware 3.0(1)b11p219,
- rg-ew1800gx pro firmware 3.0(1)b11p219,
- rg-ew300 pro firmware 3.0(1)b11p219,
- rg-ew3000gx pro firmware 3.0(1)b11p219,
- rg-ew300r firmware 3.0(1)b11p219,
- rg-ew3200gx pro firmware 3.0(1)b11p219,
- rg-nb3200-24gt4xs firmware 3.0(1)b11p219,
- rg-nbc256 firmware 3.0(1)b11p219,
- rg-nbc512 firmware 3.0(1)b11p219,
- rg-nbs1850gc firmware 3.0(1)b11p219,
- rg-nbs1850gc v2 firmware 3.0(1)b11p219,
- rg-nbs200 firmware 3.0(1)b11p219,
- rg-nbs2000 firmware 3.0(1)b11p219,
- rg-nbs2009g-p firmware 3.0(1)b11p219,
- rg-nbs2026g firmware 3.0(1)b11p219,
- rg-nbs2026g-p firmware 3.0(1)b11p219,
- rg-nbs226f firmware 3.0(1)b11p219,
- rg-nbs228f firmware 3.0(1)b11p219,
- rg-nbs252f firmware 3.0(1)b11p219,
- rg-nbs3100-24gt4sfp firmware 3.0(1)b11p219,
- rg-nbs3100-24gt4sfp-p firmware 3.0(1)b11p219,
- rg-nbs3100-24gt4sfp-p v2 firmware 3.0(1)b11p219,
- rg-nbs3100-48gt4sfp firmware 3.0(1)b11p219,
- rg-nbs3100-8gt2sfp firmware 3.0(1)b11p219,
- rg-nbs3100-8gt2sfp-p firmware 3.0(1)b11p219,
- rg-nbs3200-24gt4xs-p firmware 3.0(1)b11p219,
- rg-nbs3200-24sfp/8gt4xs firmware 3.0(1)b11p219,
- rg-nbs3200-48gt4xs firmware 3.0(1)b11p219,
- rg-nbs3200-48gt4xs-p firmware 3.0(1)b11p219,
- rg-nbs5100-24gt4sfp firmware 3.0(1)b11p219,
- rg-nbs5100-48gt4sfp firmware 3.0(1)b11p219,
- rg-nbs5200-24gt4x firmware 3.0(1)b11p219,
- rg-nbs5200-24sfp/8gt4xs firmware 3.0(1)b11p219,
- rg-nbs5200-48gt4xs firmware 3.0(1)b11p219,
- rg-nbs5300-48mg6xs firmware 3.0(1)b11p219,
- rg-nbs5528xg firmware 3.0(1)b11p219,
- rg-nbs5552xg firmware 3.0(1)b11p219,
- rg-nbs5552xg v2.0 firmware 3.0(1)b11p219,
- rg-nbs5628xg firmware 3.0(1)b11p219,
- rg-nbs5652xg firmware 3.0(1)b11p219,
- rg-nbs5710-24gt4sfp-e firmware 3.0(1)b11p219,
- rg-nbs5710-24gt4sfp-e-p firmware 3.0(1)b11p219,
- rg-nbs5710-48gt4sfp-e firmware 3.0(1)b11p219,
- rg-nbs5750-28gt4xs-e firmware 3.0(1)b11p219,
- rg-nbs5750v2-24gt4xs-e firmware 3.0(1)b11p219,
- rg-nbs5750v2-24sfp4xs-e firmware 3.0(1)b11p219,
- rg-nbs5750v2-48gt4xs-e firmware 3.0(1)b11p219,
- rg-nbs5816xs firmware 3.0(1)b11p219,
- rg-nbs6002 firmware 3.0(1)b11p219,
- rg-nbs6100-20xs4vs2qxs-s firmware 3.0(1)b11p219,
- rg-nbs7003 firmware 3.0(1)b11p219,
- rg-nbs7006 firmware 3.0(1)b11p219,
- rg-rap100 firmware 3.0(1)b11p219,
- rg-rap120 firmware 3.0(1)b11p219,
- rg-rap1200(e) firmware 3.0(1)b11p219,
- rg-rap1200(f) firmware 3.0(1)b11p219,
- rg-rap120v2 firmware 3.0(1)b11p219,
- rg-rap1260(g) firmware 3.0(1)b11p219,
- rg-rap2200(e) firmware 3.0(1)b11p219,
- rg-rap2200(f) firmware 3.0(1)b11p219,
- rg-rap2200(g) firmware 3.0(1)b11p219,
- rg-rap2260(e) firmware 3.0(1)b11p219,
- rg-rap2260(g) firmware 3.0(1)b11p219,
- rg-rap6260(g) firmware 3.0(1)b11p219,
- rg-rap6261(cd) firmware 3.0(1)b11p219,
- rg-rap6261(e) firmware 3.0(1)b11p219,
- rg-rap630cd firmware 3.0(1)b11p219,
- rg-rap630ioda firmware 3.0(1)b11p219,
- rg-s1930-24gt4sfp firmware 3.0(1)b11p219,
- rg-s1930-24t4sfp firmware 3.0(1)b11p219,
- rg-s1930-24t4sfp-p firmware 3.0(1)b11p219,
- rg-s1930-8gt2sfp firmware 3.0(1)b11p219,
- rg-s1930-8gt2sfp-p firmware 3.0(1)b11p219,
- rg-s1930-8t2sfp-p firmware 3.0(1)b11p219
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: