VYPR
Unrated severityNVD Advisory· Published Oct 6, 2023· Updated Sep 19, 2024

CVE-2023-44860

CVE-2023-44860

Description

An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization component in the HTTP request.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Improper authentication mechanism in NETIS N3Mv2 router firmware v1.0.1.865 allows remote attackers to cause denial of service via a malformed Authorization header.

Vulnerability

The vulnerability resides in the Boa web server of NETIS N3Mv2 firmware version v1.0.1.865. Improper handling of the Authorization header causes the server to crash when a malformed header is sent, e.g., Authorization: Digest username="test". This affects the firmware version v1.0.1.865 [1].

Exploitation

An attacker can exploit this vulnerability without authentication by sending a crafted HTTP request to the router's web interface. The malformed Authorization header triggers a crash in the Boa web server, leading to a denial of service. No special network position is required beyond network access to the router [1].

Impact

Successful exploitation results in a denial of service (DoS), rendering the router unresponsive and disrupting network connectivity for all connected devices. The attacker does not gain code execution or data access, but causes significant service interruption [1].

Mitigation

As of the publication date (2023-10-06), no official firmware update has been released to address this issue. Mitigations include restricting access to the router's web interface to trusted networks and monitoring for abnormal traffic patterns. Users are advised to contact the vendor for a patch or consider replacing the device if it reaches end-of-life [1].

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • NETIS SYSTEMS/N3Mv2description
  • Netis/N3Mv2llm-fuzzy
    Range: = v.1.0.1.865

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.