GreenPacket OH736's WR-1200 Indoor Unit, OT-235 with firmware versions M-IDU-1.6.0.3_V1.1 and MH-46360-2.0.3-R5-GP respectively are vulnerable to remote command injection. Commands are executed using pre-login execution and executed with root privileges allowing complete takeover.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/lionelmusonza/CVE-2023-26866 | Third Party Advisory | 
| https://github.com/lionelmusonza/CVE-2023-26866 | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
Configuration 2 (hide)
| AND | 
            
            
 
  | 
    
History
                    21 Nov 2024, 07:52
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-04-04 13:15
Updated : 2025-02-13 16:15
NVD link : CVE-2023-26866
Mitre link : CVE-2023-26866
CVE.ORG link : CVE-2023-26866
JSON object : View
Products Affected
                greenpacket
- wr-1200
 - wr-1200_firmware
 - ot-235
 - ot-235_firmware
 
CWE
                
                    
                        
                        CWE-77
                        
            Improper Neutralization of Special Elements used in a Command ('Command Injection')
