peter bassill · operator
$ cve CVE-2023-31746 JSON

CVE-2023-31746

9.8
CRITICAL · CVSS 3.1 · EPSS 3.2% (pctl 88)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

There is a command injection vulnerability in the adslr VW2100 router with firmware version M1DV1.0. An unauthenticated attacker can exploit the vulnerability to execute system commands as the root user.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.18% — more likely to be exploited than 88% of all CVEs
WeaknessCWE-77
On CISA KEVno
Public exploitnone known
Published2023-06-14
Last modified2026-06-17

Affected (2)

VendorProduct
adslrvw2100
adslrvw2100 firmware

References

→ the Explorer  ·  watch your stack  ·  NVD