Junglewise Threat Intelligence

CVE-2023-49897: FXC AE1021, AE1021PE OS Command Injection Vulnerability

CVE-2023-49897 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2023-12-21

Executive brief

FXC AE1021 and AE1021PE wireless access points contain an OS command injection vulnerability in their firmware. Authenticated attackers with network access can execute arbitrary OS commands on the device. This vulnerability has been observed being exploited in the wild, including by Mirai-like botnets.

Affected products

  • FXC AE1021 firmware up to (excluding) 2.0.10
  • FXC AE1021PE firmware up to (excluding) 2.0.10

Timeline

  • 2023-12-06: advisory: Vendor advisory released by FXC
  • 2023-12-21: disclosed: Initial publication date
  • 2023-12-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-12-21: exploited: Reported as exploited in the wild by Akamai and CISA