ZeroHour

CVE-2023-49897

KEV PoC

OS Command Injection in FXC AE1021/AE1021PE Routers Exploited in the Wild

CISA: FXC AE1021, AE1021PE OS Command Injection Vulnerability

CVSS 3.1
8.8 high
EPSS
50%p99
Published
()
KEV added
AI analysis

An OS command injection flaw (CWE-78) exists in FXC AE1021 and AE1021PE router firmware versions 2.0.9 and earlier. An attacker who is able to log in to the device can submit crafted input that the firmware passes to the underlying operating system, causing arbitrary OS commands to be executed. Successful exploitation yields arbitrary command execution on the router with high impact across confidentiality, integrity, and availability (CVSS 3.1 8.8), effectively giving the attacker control of the device. Any user or organization running AE1021 or AE1021PE firmware 2.0.9 or earlier is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-21, and public Akamai research ties it to a Mirai-based botnet campaign exploiting these routers for DDoS activity, with a 50.4% EPSS probability of exploitation over the next 30 days (99th percentile).

What to do: Upgrade AE1021 and AE1021PE devices to the latest FXC firmware (any version newer than 2.0.9), per the vendor advisory and the CISA KEV required action; if patching is not possible, discontinue use of the product or restrict its management interface to trusted networks with strong login credentials. Review devices for signs of compromise, such as unexpected outbound connections or changed credentials, since a Mirai-based botnet campaign has been observed exploiting these routers.

Affected
FXC AE1021PE firmware2.0.9 and earlier
FXC AE1021 firmware2.0.9 and earlier
Estimated exposure
unknown precise count; plausibly on the order of tens of thousands of deployed units — No public install-base, market-share, or internet-exposure scan data for these single-vendor SOHO broadband routers (typically deployed via Japanese ISPs and small offices) is available in this dataset, so the magnitude is only a…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.

CISA Known Exploited Vulnerability
Affected
FXC AE1021, AE1021PE
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
fxc
Products
ae1021 firmware, ae1021pe firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news