CVE-2023-33530
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Jun 6, 2023
Updated: Jan 8, 2025
CWE ID 77
Summary
CVE-2023-33530 is a command injection vulnerability affecting the Tenda G103 Gigabit GPON Terminal with firmware version V1.0.0.5. If an attacker manages to obtain web management privileges, they can exploit this flaw to inject commands and ultimately gain shell privileges. This vulnerability poses a serious threat and requires prompt attention from users and organizations running the affected device. It is strongly recommended to update the firmware to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Shenzhen Tenda Technology Co. Ltd