CVE-2023-0862 Details
Description
The NetModule NSRW web administration interface is vulnerable to path traversals, which could lead to arbitrary file uploads and deletion. By uploading malicious files to the web root directory, authenticated users could gain remote command execution with elevated privileges. This issue affects NSRW: from 4.3.0.0 before 4.3.0.119, from 4.4.0.0 before 4.4.0.118, from 4.6.0.0 before 4.6.0.105, from 4.7.0.0 before 4.7.0.103.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 18, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://onekey.com/blog/security-advisory-netmodule-multiple-vulnerabilities/ | CVE | Third Party Advisory |
| https://share.netmodule.com/public/system-software/4.7/4.7.0.103/NRSW-RN-4.7.0.103.pdf | CVE | Release NotesVendor Advisory |
| https://onekey.com/blog/security-advisory-netmodule-multiple-vulnerabilities/ | [email protected] | Third Party Advisory |
| https://share.netmodule.com/public/system-software/4.7/4.7.0.103/NRSW-RN-4.7.0.103.pdf | [email protected] | Release NotesVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| netmodule netmodule router software | >= 4.3.0.0, < 4.3.0.119 >= 4.4.0.0, < 4.4.0.118 >= 4.6.0.0, < 4.6.0.105 >= 4.7.0.0, < 4.7.0.103 |
CPE
Remediation
| |
| netmodule nb1601 | All versions |
CPE
Remediation
| |
| netmodule nb1800 | All versions |
CPE
Remediation
| |
| netmodule nb1810 | All versions |
CPE
Remediation
| |
| netmodule nb2800 | All versions |
CPE
Remediation
| |
| netmodule nb2810 | All versions |
CPE
Remediation
| |
| netmodule nb3701 | All versions |
CPE
Remediation
| |
| netmodule nb3800 | All versions |
CPE
Remediation
| |
| netmodule nb800 | All versions |
CPE
Remediation
| |
| netmodule ng800 | All versions |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Nov 7, 2023 | CVE Modified | [email protected] |
| Nov 2, 2023 | Reanalysis | [email protected] |
| Feb 24, 2023 | Initial Analysis | [email protected] |
| Feb 21, 2023 | CVE Modified | [email protected] |