File Upload vulnerability in Digital China Networks DCFW-1800-SDC v.3.0 allows an authenticated attacker to execute arbitrary code via the wget function in the /sbin/cloudadmin.sh component.
References
Link | Resource |
---|---|
https://github.com/Push3AX/vul/blob/main/DCN/DCFW_1800_SDC_CommandInjection.md | Exploit Third Party Advisory |
https://www.dcnetworks.com.cn/goods/61.html | Product |
https://github.com/Push3AX/vul/blob/main/DCN/DCFW_1800_SDC_CommandInjection.md | Exploit Third Party Advisory |
https://www.dcnetworks.com.cn/goods/61.html | Product |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 08:23
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-10-04 22:15
Updated : 2024-11-21 08:23
NVD link : CVE-2023-43321
Mitre link : CVE-2023-43321
CVE.ORG link : CVE-2023-43321
JSON object : View
Products Affected
dcnetworks
- dcfw-1800-sdc
- dcfw-1800-sdc_firmware
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type