Skip to main content
CRITICAL

CVE-2023-40146

CVSS v3

9.8

CRITICAL

EPSS Score

1.0 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to a limited-shell escape and elevated capabilities. An attacker can authenticate with hard-coded credentials and execute unblocked default busybox functionality to trigger this vulnerability.

Technical details

Published
2024-04-17

Frequently asked questions

What is CVE-2023-40146?

A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to a limited-shell escape and elevated capabilities. An attacker can authenticate with hard-coded credentials and execute unblocked default busybox functionality to trigger this vulnerability.

Is CVE-2023-40146 actively exploited?

Active exploitation of CVE-2023-40146 has not been confirmed. The EPSS score is 1.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-40146?

CVE-2023-40146 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2023-40146 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key