Lucene search

K
cvelistMediaTekCVELIST:CVE-2023-20820
HistorySep 04, 2023 - 2:27 a.m.

CVE-2023-20820

2023-09-0402:27:15
MediaTek
www.cve.org
2
wlan service
command injection
remote code execution
input validation

EPSS

0.002

Percentile

51.9%

In wlan service, there is a possible command injection due to improper input validation. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00244189; Issue ID: WCNCR00244189.

CNA Affected

[
  {
    "vendor": "MediaTek, Inc.",
    "product": "MT6890, MT7603, MT7612, MT7613, MT7615, MT7622, MT7626, MT7629, MT7915, MT7916, MT7981, MT7986, MT7990",
    "versions": [
      {
        "version": "OpenWRT 19.07, 21.02",
        "status": "affected"
      }
    ]
  }
]

EPSS

0.002

Percentile

51.9%

Related for CVELIST:CVE-2023-20820