CVE-2023-49897 Details
Description
An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
A command injection vulnerability allowing authenticated users to execute arbitrary operating system commands exists in FXC AE1021PE and AE1021 wireless LAN routers, both running firmware versions through 2.0.9. This vulnerability can be exploited via the management interface using default credentials.
Users are advised to update the router's firmware to version 2.0.10, reset the device to factory settings, and change the default management screen login password. For more information, see FXC's firmware update announcement.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Dec 20, 2023References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-49897 | CISA-ADP | US Government Resource |
| https://jvn.jp/en/vu/JVNVU92152057/ | CVE | Third Party Advisory |
| https://www.akamai.com/blog/security-research/zero-day-vulnerability-spreading-mirai-patched | CVE | ExploitThird Party Advisory |
| https://www.cisa.gov/news-events/ics-advisories/icsa-23-355-01 | CVE | Third Party AdvisoryUS Government Resource |
| https://www.fxc.jp/news/20231206 | CVE | Release NotesVendor Advisory |
| https://jvn.jp/en/vu/JVNVU92152057/ | [email protected] | Third Party Advisory |
| https://www.akamai.com/blog/security-research/zero-day-vulnerability-spreading-mirai-patched | [email protected] | ExploitThird Party Advisory |
| https://www.cisa.gov/news-events/ics-advisories/icsa-23-355-01 | [email protected] | Third Party AdvisoryUS Government Resource |
| https://www.fxc.jp/news/20231206 | [email protected] | Release NotesVendor Advisory |
This CVE is in CISA's Known Exploited Vulnerabilities Catalog
Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.
| Vulnerability Name | Date Added | Due Date | Required Action |
|---|---|---|---|
| FXC AE1021, AE1021PE OS Command Injection Vulnerability | Dec 21, 2023 | Jan 11, 2024 | Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | [email protected] |
| CWE-78 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| fxc ae1021 firmware | < 2.0.10 |
CPE
Remediation
| |
| fxc ae1021 | All versions |
CPE
Remediation
| |
| fxc ae1021pe firmware | < 2.0.10 |
CPE
Remediation
| |
| fxc ae1021pe | All versions |
CPE
Remediation
| |
Change History
16 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 24, 2025 | Modified Analysis | [email protected] |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Oct 21, 2025 | CVE Modified | CISA-ADP |
| Feb 4, 2025 | Modified Analysis | [email protected] |
| Feb 3, 2025 | CVE Modified | CISA-ADP |
| Jan 27, 2025 | Modified Analysis | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| Jun 11, 2024 | Modified Analysis | [email protected] |
| May 14, 2024 | CVE Modified | [email protected] |
| Dec 22, 2023 | CVE Modified | [email protected] |
| Dec 22, 2023 | CVE CISA KEV Update | Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government |
| Dec 11, 2023 | Initial Analysis | [email protected] |
| Dec 6, 2023 | New CVE Received | [email protected] |