CVE Feed

    Dashboard / CVE / CVE-2023-23912

    CVE-2023-23912

    A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with their DHCPv6 prefix delegation set to dhcpv6-stateless or dhcpv6-stateful, allows a malicious actor directly connected to the WAN interface of an affected device to create a remote code execution vulnerability.

    Published:Feb 9, 2023
    Last Modified:Mar 24, 2025
    EPS:Feb 9, 2023
    EPSS Score:0.01742
    CVSS Score:8.8

    Affected Products

    Vendor
    Ui
    Product
    Er-10x
    Vendor
    Ui
    Product
    Er-10x Firmware
    Vendor
    Ui
    Product
    Er-12
    Vendor
    Ui
    Product
    Er-12 Firmware
    Vendor
    Ui
    Product
    Er-12p
    Vendor
    Ui
    Product
    Er-12p Firmware
    Vendor
    Ui
    Product
    Er-4
    Vendor
    Ui
    Product
    Er-4 Firmware
    Vendor
    Ui
    Product
    Er-6p
    Vendor
    Ui
    Product
    Er-6p Firmware
    Vendor
    Ui
    Product
    Er-8-xg
    Vendor
    Ui
    Product
    Er-8-xg Firmware
    Vendor
    Ui
    Product
    Er-x
    Vendor
    Ui
    Product
    Er-x-sfp
    Vendor
    Ui
    Product
    Er-x-sfp Firmware
    Vendor
    Ui
    Product
    Er-x Firmware
    Vendor
    Ui
    Product
    Usg
    Vendor
    Ui
    Product
    Usg-pro-4
    Vendor
    Ui
    Product
    Usg-pro-4 Firmware
    Vendor
    Ui
    Product
    Usg Firmware

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High