CVE-2023-43893
Description
Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) function. This vulnerability is exploited via a crafted payload.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Blind command injection in Netis N3Mv2 router's Wake-On-LAN function via the wakeup_mac parameter allows arbitrary OS command execution.
Vulnerability
The Netis N3Mv2 router firmware version V1.0.1.865 contains a blind command injection vulnerability in the Wake-On-LAN (WoL) functionality. The flaw resides in the handling of the wakeup_mac parameter used for initiating WoL requests. An attacker can inject arbitrary OS commands via this parameter without any authentication requirement [1].
Exploitation
An attacker can craft a malicious payload in the wakeup_mac parameter of the WoL request, which is then processed by the router's firmware without proper sanitization. The attack requires network access to the router, but no prior authentication is needed. The command injection is blind, meaning the attacker does not receive direct output, but can execute commands that affect the router's behavior [1].
Impact
Successful exploitation allows an attacker to execute arbitrary OS commands on the router, potentially leading to full compromise of the device, unauthorized access to internal networks, data exfiltration, or further attacks against other devices [1].
Mitigation
As of the available references [1], no fixed version has been released by Netis for this vulnerability. Users should monitor vendor advisories for a firmware update. A potential workaround includes disabling the Wake-On-LAN feature if not required until a patch is applied [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Netis/N3Mv2description
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.