CVE-2023-46306 | NetModule Router Software prior 4.6.0.106/4.8.0.101 Web Administration Interface /admin/gnssAutoAlign.php cleanup device_id os command injection (EUVD-2023-50528)
A vulnerability was found in NetModule Router Software and classified as critical. This impacts the function cleanup of the file /admin/gnssAutoAlign.php of the component Web Administration Interface. Executing a manipulation of the argument device_id can lead to os command injection.
This vulnerability is tracked as CVE-2023-46306. The attack is only possible within the local network. No exploit exists.
It is suggested to upgrade the affected component.