CVE-2023-31746

T

here is a command injection vulnerability in the adslr VW2100 router with firmware version M1DV1.0. An unauthenticated attacker can exploit the vulnerability to execute system commands as the root user.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:adslr:vw2100_firmware:m1dv1.0:*:*:*:*:*:*:*
cpe:2.3:h:adslr:vw2100:-:*:*:*:*:*:*:*

History

01 Aug 2025, 02:11

Type Values Removed Values Added
First Time Adslr vw2100 Firmware
Adslr vw2100
Adslr
Summary
  • (es) Existe una vulnerabilidad de inyección de comandos en el router adslr VW2100 con la versión de firmware M1DV1.0. Un atacante no autenticado puede aprovechar esta vulnerabilidad para ejecutar comandos del sistema como usuario root.
CPE cpe:2.3:h:vw2100_project:vw2100:-:*:*:*:*:*:*:*
cpe:2.3:o:vw2100_project:vw2100_firmware:m1dv1.0:*:*:*:*:*:*:*
cpe:2.3:h:adslr:vw2100:-:*:*:*:*:*:*:*
cpe:2.3:o:adslr:vw2100_firmware:m1dv1.0:*:*:*:*:*:*:*

21 Nov 2024, 08:02

Type Values Removed Values Added
References () https://github.com/D2y6p/CVE/blob/main/adslr/CVE-2023-31746/1/VW2100_RCE1.pdf - Broken Link, Third Party Advisory () https://github.com/D2y6p/CVE/blob/main/adslr/CVE-2023-31746/1/VW2100_RCE1.pdf - Broken Link, Third Party Advisory
References () https://github.com/D2y6p/CVE/blob/main/adslr/CVE-2023-31746/2/VW2100_RCE2.pdf - Broken Link, Third Party Advisory () https://github.com/D2y6p/CVE/blob/main/adslr/CVE-2023-31746/2/VW2100_RCE2.pdf - Broken Link, Third Party Advisory
References () https://github.com/D2y6p/CVE/blob/main/adslr/CVE-2023-31746/3/VW2100_RCE3.pdf - Broken Link, Third Party Advisory () https://github.com/D2y6p/CVE/blob/main/adslr/CVE-2023-31746/3/VW2100_RCE3.pdf - Broken Link, Third Party Advisory
References () https://github.com/D2y6p/CVE/blob/main/adslr/CVE-2023-31746/4/VW2100_RCE4.pdf - Broken Link, Third Party Advisory () https://github.com/D2y6p/CVE/blob/main/adslr/CVE-2023-31746/4/VW2100_RCE4.pdf - Broken Link, Third Party Advisory

Information

Published : 2023-06-14 21:15

Updated : 2025-08-01 02:11


NVD link : CVE-2023-31746

Mitre link : CVE-2023-31746

CVE.ORG link : CVE-2023-31746


JSON object : View

Products Affected
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')