CVE-2023-38902 (rg-eap101_firmware, rg-eap101_v2_firmware, rg-eap102(f)_firmware, rg-eap102_firmware, rg-eap102_v2_firmware, rg-eap162(g)_firmware, rg-eap201_firmware, rg-eap202_firmware, rg-eap212(f)_firmware, rg-eap212(g)_firmware, rg-eap262(g)_firmware, rg-eap602_firmware, rg-eap662(g)_firmware, rg-eg105g-e_firmware, rg-eg105g-pe_firmware, rg-eg105g_v2_firmware, rg-eg210g-e_firmware, rg-eg210g-p_firmware, rg-eg210g-pe_firmware, rg-ew1200_firmware, rg-ew1200g_pro_firmware, rg-ew1200r_firmware, rg-ew1300g_firmware, rg-ew1800gx_pro_firmware, rg-ew300_pro_firmware, rg-ew3000gx_pro_firmware, rg-ew300r_firmware, rg-ew3200gx_pro_firmware, rg-nb3200-24gt4xs_firmware, rg-nbc256_firmware, rg-nbc512_firmware, rg-nbs1850gc_firmware, rg-nbs1850gc_v2_firmware, rg-nbs200_firmware, rg-nbs2000_firmware, rg-nbs2009g-p_firmware, rg-nbs2026g-p_firmware, rg-nbs2026g_firmware, rg-nbs226f_firmware, rg-nbs228f_firmware, rg-nbs252f_firmware, rg-nbs3100-24gt4sfp-p_firmware, rg-nbs3100-24gt4sfp-p_v2_firmware, rg-nbs3100-24gt4sfp_firmware, rg-nbs3100-48gt4sfp_firmware, rg-nbs3100-8gt2sfp-p_firmware, rg-nbs3100-8gt2sfp_firmware, rg-nbs3200-24gt4xs-p_firmware, rg-nbs3200-24sfp/8gt4xs_firmware, rg-nbs3200-48gt4xs-p_firmware, rg-nbs3200-48gt4xs_firmware, rg-nbs5100-24gt4sfp_firmware, rg-nbs5100-48gt4sfp_firmware, rg-nbs5200-24gt4x_firmware, rg-nbs5200-24sfp/8gt4xs_firmware, rg-nbs5200-48gt4xs_firmware, rg-nbs5300-48mg6xs_firmware, rg-nbs5528xg_firmware, rg-nbs5552xg_firmware, rg-nbs5552xg_v2.0_firmware, rg-nbs5628xg_firmware, rg-nbs5652xg_firmware, rg-nbs5710-24gt4sfp-e-p_firmware, rg-nbs5710-24gt4sfp-e_firmware, rg-nbs5710-48gt4sfp-e_firmware, rg-nbs5750-28gt4xs-e_firmware, rg-nbs5750v2-24gt4xs-e_firmware, rg-nbs5750v2-24sfp4xs-e_firmware, rg-nbs5750v2-48gt4xs-e_firmware, rg-nbs5816xs_firmware, rg-nbs6002_firmware, rg-nbs6100-20xs4vs2qxs-s_firmware, rg-nbs7003_firmware, rg-nbs7006_firmware, rg-rap100_firmware, rg-rap120_firmware, rg-rap1200(e)_firmware, rg-rap1200(f)_firmware, rg-rap120v2_firmware, rg-rap1260(g)_firmware, rg-rap2200(e)_firmware, rg-rap2200(f)_firmware, rg-rap2200(g)_firmware, rg-rap2260(e)_firmware, rg-rap2260(g)_firmware, rg-rap6260(g)_firmware, rg-rap6261(cd)_firmware, rg-rap6261(e)_firmware, rg-rap630cd_firmware, rg-rap630ioda_firmware, rg-s1930-24gt4sfp_firmware, rg-s1930-24t4sfp-p_firmware, rg-s1930-24t4sfp_firmware, rg-s1930-8gt2sfp-p_firmware, rg-s1930-8gt2sfp_firmware, rg-s1930-8t2sfp-p_firmware)

A command injection vulnerability in RG-EW series home routers and repeaters v.EW_3.0(1)B11P219, RG-NBS and RG-S1930 series switches v.SWITCH_3.0(1)B11P219, RG-EG series business VPN routers v.EG_3.0(1)B11P219, EAP and RAP series wireless access points v.AP_3.0(1)B11P219, and NBC series wireless controllers v.AC_3.0(1)B11P219 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /cgi-bin/luci/api/cmd via the remoteIp field.Read More