CVE-2023-38829 is a high-severity vulnerability affecting NETIS SYSTEMS WF2409E v.3.6.42541, allowing remote attackers to execute arbitrary code through the diagnostic tools' ping and traceroute functions in the admin interface. With a CVSS score of 8.8 (High), it presents a low-complexity attack vector (AC:L) that can lead to complete compromise of confidentiality, integrity, and availability (C:H/I:H/A:H) once an attacker gains authenticated access (PR:L). While the EPSS score indicates a higher-than-average exploitability probability compared to most CVEs, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.6.42541CPE matchmatch criteria | cpe:2.3:o:netis-systems:wf2409e_firmware:3.6.42541:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.