VYPR
Unrated severityNVD Advisory· Published Oct 2, 2023· Updated Sep 20, 2024

CVE-2023-43891

CVE-2023-43891

Description

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability is exploited via a crafted payload.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Netis N3Mv2-V1.0.1.865 router suffers from a command injection in the password change feature, allowing unauthenticated arbitrary command execution.

Vulnerability

Netis N3Mv2-V1.0.1.865 router firmware contains a command injection vulnerability in the "Changing Username and Password" function (FUN_00408dd0). The function uses RunSystemCmd with user-supplied username and password strings without proper sanitization, allowing an attacker to inject arbitrary commands. The affected version is Netis N3Mv2-V1.0.1.865 [1].

Exploitation

An attacker with network access to the router's web interface can send a crafted HTTP request to the password change endpoint. By embedding command separators (e.g., ;, |, or backticks) in the username or password fields, the injected command is executed by the router. No prior authentication is required as the vulnerable function is accessible without login [1].

Impact

Successful exploitation allows an unauthenticated attacker to execute arbitrary commands with root privileges on the router. This can lead to full device compromise, including data exfiltration, installation of malware, and use of the router as a pivot for further network attacks [1].

Mitigation

As of the publication date, no official patch has been released by Netis. Users are advised to restrict remote access to the router's web interface, change default credentials, and monitor for firmware updates from the vendor. If possible, disable the password change feature until a fix is available [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Netis/N3Mv2description
  • Netis/N3Mv2llm-fuzzy
    Range: = V1.0.1.865

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.