CVE-2023-31198
Description
OS command injection vulnerability exists in Wi-Fi AP UNIT allows. If this vulnerability is exploited, a remote authenticated attacker with an administrative privilege to execute an arbitrary OS command. Affected products and versions are as follows: AC-PD-WAPU v1.05_B04 and earlier, AC-PD-WAPUM v1.05_B04 and earlier, AC-PD-WAPU-P v1.05_B04P and earlier, AC-PD-WAPUM-P v1.05_B04P and earlier, AC-WAPU-300 v1.00_B07 and earlier, AC-WAPUM-300 v1.00_B07 and earlier, AC-WAPU-300-P v1.00_B07 and earlier, and AC-WAPUM-300-P v1.00_B07 and earlier
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An authenticated admin can inject arbitrary OS commands via a crafted request in multiple Inaba Denki Sangyo Wi-Fi AP UNIT models before patched versions.
Vulnerability
An OS command injection vulnerability (CWE-78) exists in the administrative web interface of Inaba Denki Sangyo Wi-Fi AP UNIT products. Affected versions are: AC-PD-WAPU v1.05_B04 and earlier, AC-PD-WAPUM v1.05_B04 and earlier, AC-PD-WAPU-P v1.05_B04P and earlier, AC-PD-WAPUM-P v1.05_B04P and earlier, AC-WAPU-300 v1.00_B07 and earlier, AC-WAPUM-300 v1.00_B07 and earlier, AC-WAPU-300-P v1.00_B07 and earlier, and AC-WAPUM-300-P v1.00_B07 and earlier [1]. The flaw allows injection of arbitrary system commands through specially crafted input parameters accessible to authenticated administrative users.
Exploitation
An attacker must first authenticate with administrative privileges to the device's management interface. Once authenticated, the attacker sends a specially crafted HTTP request containing operating system commands within the vulnerable parameter [1]. No user interaction beyond normal administrator operations is required.
Impact
Successful exploitation grants the attacker the ability to execute arbitrary OS commands with the privileges of the web server process, typically root or a highly privileged user [1]. This leads to full compromise of the device (confidentiality, integrity, availability), potentially allowing the attacker to install malware, exfiltrate network traffic, or pivot to internal networks.
Mitigation
The developer has announced that these products are end-of-life and no patches will be provided [1]. Users are advised to apply workarounds such as restricting network access to the management interface via firewall rules and disabling remote management if not required. The vendor recommends replacing the affected devices with supported alternatives.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: <= v1.05_B04
- Inaba Denki Sangyo Co., Ltd./Wi-Fi AP UNITv5Range: AC-PD-WAPU v1.05_B04 and earlier, AC-PD-WAPUM v1.05_B04 and earlier, AC-PD-WAPU-P v1.05_B04P and earlier, AC-PD-WAPUM-P v1.05_B04P and earlier, AC-WAPU-300 v1.00_B07 and earlier, AC-WAPUM-300 v1.00_B07 and earlier, AC-WAPU-300-P v1.00_B07 and earlier, and AC-WAPUM-300-P v1.00_B07 and earlier
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.