VYPR
Unrated severityNVD Advisory· Published Oct 2, 2023· Updated Sep 20, 2024

CVE-2023-43893

CVE-2023-43893

Description

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) function. This vulnerability is exploited via a crafted payload.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Blind command injection in Netis N3Mv2 router's Wake-On-LAN function via the wakeup_mac parameter allows arbitrary OS command execution.

Vulnerability

The Netis N3Mv2 router firmware version V1.0.1.865 contains a blind command injection vulnerability in the Wake-On-LAN (WoL) functionality. The flaw resides in the handling of the wakeup_mac parameter used for initiating WoL requests. An attacker can inject arbitrary OS commands via this parameter without any authentication requirement [1].

Exploitation

An attacker can craft a malicious payload in the wakeup_mac parameter of the WoL request, which is then processed by the router's firmware without proper sanitization. The attack requires network access to the router, but no prior authentication is needed. The command injection is blind, meaning the attacker does not receive direct output, but can execute commands that affect the router's behavior [1].

Impact

Successful exploitation allows an attacker to execute arbitrary OS commands on the router, potentially leading to full compromise of the device, unauthorized access to internal networks, data exfiltration, or further attacks against other devices [1].

Mitigation

As of the available references [1], no fixed version has been released by Netis for this vulnerability. Users should monitor vendor advisories for a firmware update. A potential workaround includes disabling the Wake-On-LAN feature if not required until a patch is applied [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Netis/N3Mv2description
  • Netis/N3Mv2llm-fuzzy
    Range: V1.0.1.865

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.