CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.8. See the original NVD description below for full technical details.
CVE
CVE-2023-40146
Severity
MEDIUM
CVSS
6.8
EPSS
1.44%
Original NVD Description
A privilege escalation vulnerability exists in the /bin/login functionality of Peplink Smart Reader v1.2.0 (in QEMU). A specially crafted command line argument can lead to a limited-shell escape and elevated capabilities. An attacker can authenticate with hard-coded credentials and execute unblocked default busybox functionality to trigger this vulnerability.
Related CVEs
Other vulnerabilities affecting the same vendor(s)