VYPR
Unrated severityNVD Advisory· Published Oct 13, 2023· Updated Sep 18, 2024

CVE-2023-45465

CVE-2023-45465

Description

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ddnsDomainName parameter in the Dynamic DNS settings.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Netis N3Mv2-V1.0.1.865 router contains a blind command injection vulnerability in the ddnsDomainName parameter of Dynamic DNS settings, enabling remote attackers to execute arbitrary OS commands.

Vulnerability

The Netis N3Mv2 router firmware version V1.0.1.865 is vulnerable to a blind OS command injection in the ddnsDomainName parameter within the Dynamic DNS (DDNS) settings page. The parameter is not properly sanitized before being used in a system command, allowing injection of arbitrary commands. [1]

Exploitation

An attacker can exploit this vulnerability by sending a crafted HTTP request to the router's web interface, specifically targeting the DDNS configuration endpoint with a malicious ddnsDomainName value. The injection is blind, meaning the attacker does not receive direct output but can infer command execution through side effects (e.g., time delays or out-of-band interactions). No authentication is explicitly required in the disclosure, but typical router interfaces require administrative credentials to access the DDNS settings. [1]

Impact

Successful exploitation allows an attacker to execute arbitrary OS commands on the router with root privileges, leading to full compromise of the device. This can result in unauthorized access, data exfiltration, and use of the router as a pivot point for further network attacks. [1]

Mitigation

As of the publication date (2023-10-13), no official patch or firmware update has been released by Netis to address this vulnerability. Users are advised to monitor the vendor's support page for updates. If the device is no longer supported, consider replacing it with a patched or more secure alternative. [1]

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • Netis/N3Mv2description
  • Netis/N3Mv2llm-fuzzy
    Range: = V1.0.1.865

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.