CVE-2023-49897
KEV PoCOS Command Injection in FXC AE1021/AE1021PE Routers Exploited in the Wild
CISA: FXC AE1021, AE1021PE OS Command Injection Vulnerability
An OS command injection flaw (CWE-78) exists in FXC AE1021 and AE1021PE router firmware versions 2.0.9 and earlier. An attacker who is able to log in to the device can submit crafted input that the firmware passes to the underlying operating system, causing arbitrary OS commands to be executed. Successful exploitation yields arbitrary command execution on the router with high impact across confidentiality, integrity, and availability (CVSS 3.1 8.8), effectively giving the attacker control of the device. Any user or organization running AE1021 or AE1021PE firmware 2.0.9 or earlier is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-21, and public Akamai research ties it to a Mirai-based botnet campaign exploiting these routers for DDoS activity, with a 50.4% EPSS probability of exploitation over the next 30 days (99th percentile).
What to do: Upgrade AE1021 and AE1021PE devices to the latest FXC firmware (any version newer than 2.0.9), per the vendor advisory and the CISA KEV required action; if patching is not possible, discontinue use of the product or restrict its management interface to trusted networks with strong login credentials. Review devices for signs of compromise, such as unexpected outbound connections or changed credentials, since a Mirai-based botnet campaign has been observed exploiting these routers.
| FXC AE1021PE firmware | 2.0.9 and earlier |
| FXC AE1021 firmware | 2.0.9 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product.
- Affected
- FXC AE1021, AE1021PE
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- fxc
- Products
- ae1021 firmware, ae1021pe firmware
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H