CVE-2023-0351 describes a command injection vulnerability in the Akuvox E11 web server backend library, specifically within its phone-book contacts functionality, affecting Akuvox E11 devices and their firmware. This high-severity flaw (CVSS 8.8) allows authenticated remote attackers to upload files containing executable commands, potentially leading to full compromise (confidentiality, integrity, availability). While there are no public exploits or active exploitation reported, the vulnerability has garnered some community discussion and media coverage, indicating awareness of its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:akuvox:e11_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.