← Back to browse · API

CVE-2023-39367

Severity
CRITICAL
CVSS
9.1
EPSS
0.37678
Risk score
49.59
CISA KEV
No
PoC
No
Published
2024-04-17
Modified
2025-11-04
First seen
2026-08-07
Aliases
EUVD-2023-43092, GHSA-R4RF-J49F-C6Q2
Products
Peplink:Smart Reader v1.2.0 (in QEMU)
Sources
euvd EUVD-2023-43092

Description

An OS command injection vulnerability exists in the web interface mac2name functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

References