High severity8.8NVD Advisory· Published Feb 23, 2023· Updated Jun 17, 2026
CVE-2023-23294
CVE-2023-23294
Description
Korenix JetWave 4200 Series 1.3.0 and JetWave 3000 Series 1.6.0 are vulnerable to Command Injection. An attacker can modify the file_name parameter to execute commands as root.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17- cpe:2.3:o:korenix:jetwave_2212g_firmware:1.3.t:*:*:*:*:*:*:*
- cpe:2.3:o:korenix:jetwave_2212s_firmware:1.3.0:*:*:*:*:*:*:*
- cpe:2.3:o:korenix:jetwave_2212x_firmware:1.3.0:*:*:*:*:*:*:*
- cpe:2.3:o:korenix:jetwave_3220_v3__firmware:*:*:*:*:*:*:*:*Range: <1.7
- cpe:2.3:o:korenix:jetwave_3420_v3__firmware:*:*:*:*:*:*:*:*Range: <1.7
- cpe:2.3:o:korenix:jetwave_4221hp-e__firmware:*:*:*:*:*:*:*:*Range: <=1.3.0
- Korenix/JetWave 4200 Seriesdescription
- Range: =1.3.0
Patches
Vulnerability mechanics
References
1- cyberdanube.com/en/en-multiple-vulnerabilities-in-korenix-jetwave-series/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.