CVE-2023-50382
Three os command injection vulnerabilities exist in the boa formWsc functionality of Realtek rtl819x Jungle SDK v3.4.11. A specially crafted series of HTTP requests can lead to arbitrary command execution. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This command injection is related to the `peerPin` request's parameter.
Published:Jul 8, 2024
Last Modified:Nov 4, 2025
EPS:Jul 8, 2024
EPSS Score:0.00304
CVSS Score:7.2
Affected Products
Vendor
Product
Action
Vendor
Level1
Product
Wbr-6013
Level1
Wbr-6013
Vendor
Level1
Product
Wbr-6013 Firmware
Level1
Wbr-6013 Firmware
Vendor
Levelone
Product
Wbr-6013
Levelone
Wbr-6013
Vendor
Realtek
Product
Rtl819x Jungle Software Development Kit
Realtek
Rtl819x Jungle Software Development Kit
Vendor
Realtek
Product
Rtl819x Software Development Kit
Realtek
Rtl819x Software Development Kit
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
