← All CVEs

CVE-2023-49897

high · 8.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added 2023-12-21Remediation due 2024-01-11

An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

8.8
CVSS
50.4%
EPSS (exploit prob.)
99th
EPSS percentile
2023-12-06
Published

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-78

Affected products

VendorProductAffected versions
fxcae1021_firmware< 2.0.10
fxcae1021all versions
fxcae1021pe_firmware< 2.0.10
fxcae1021peall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2023-49897