CVE-2023-49897 is an OS command injection vulnerability affecting FXC AE1021 and AE1021PE firmware versions 2.0.9 and earlier. This high-severity vulnerability (CVSS 8.8) allows an authenticated attacker to execute arbitrary OS commands, potentially leading to full compromise of the device. It is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog, and has garnered significant community and media attention, despite no public exploit code being readily available. The ease of exploitation is heightened by the common use of default credentials.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.10CPE matchmatch criteria | cpe:2.3:o:fxc:ae1021_firmware:*:*:*:*:*:*:*:* | ||
< 2.0.10CPE matchmatch criteria | cpe:2.3:o:fxc:ae1021pe_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.