VYPR
Unrated severityNVD Advisory· Published Oct 2, 2023· Updated Sep 20, 2024

CVE-2023-43890

CVE-2023-43890

Description

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the diagnostic tools page. This vulnerability is exploited via a crafted HTTP request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Netis N3Mv2-V1.0.1.865 router diagnostic tools page contains a command injection vulnerability bypassing filters, allowing authenticated remote attackers to execute OS commands as root.

Vulnerability

The Netis N3Mv2 router firmware version V1.0.1.865 contains a command injection vulnerability in the diagnostic tools page, specifically in the ping and traceroute functions. The affected code uses a check that rejects input containing spaces, |, ;, or & characters, but the filter can be bypassed because it does not block other command injection techniques such as backticks or $() substitution. The vulnerability resides in the function FUN_0040bd60 which processes the IpAddr parameter [1].

Exploitation

An attacker must have administrative access to the router's web interface. The attacker can craft a HTTP request to the diagnostic tools page with a payload in the IpAddr field that bypasses the filter (e.g., using backticks or $()). The application then passes the unsanitized input directly into a ping or traceroute command executed via system() [1].

Impact

Successful exploitation allows the authenticated attacker to execute arbitrary OS commands on the router as the root user, leading to full compromise of the device. This can result in unauthorized network access, data exfiltration, or using the device as a pivot point [1].

Mitigation

As of the published advisory [1], no official firmware patch has been released by Netis. Administrators should restrict access to the web management interface, disable remote management if possible, and monitor for anomalous traffic. The affected version is Netis N3Mv2-V1.0.1.865. Users should check the vendor's website for future firmware updates [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Netis/N3Mv2description
  • Netis/N3Mv2llm-fuzzy
    Range: = V1.0.1.865

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.