An OS Command Injection in the CLI interface on DrayTek Vigor167 version 5.2.2, allows remote attackers to execute arbitrary system commands and escalate privileges via any account created within the web interface.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2023-12-09T00:00:00

Updated: 2023-12-09T07:12:17.381473

Reserved: 2023-11-05T00:00:00


Link: CVE-2023-47254

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-12-09T08:15:06.787

Modified: 2023-12-12T22:33:48.820


Link: CVE-2023-47254

JSON object: View

cve-icon Redhat Information

No data.

CWE