ZeroHour

Vulnerabilities

2 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-49897
OS Command Injection in FXC AE1021/AE1021PE Routers Exploited in the Wild

An OS command injection flaw (CWE-78) exists in FXC AE1021 and AE1021PE router firmware versions 2.0.9 and earlier. An attacker who is able to log in to the device can submit crafted input that the firmware passes to the underlying operating system, causing arbitrary OS commands to be executed. Successful exploitation yields arbitrary command execution on the router with high impact across confidentiality, integrity, and availability (CVSS 3.1 8.8), effectively giving the attacker control of the device. Any user or organization running AE1021 or AE1021PE firmware 2.0.9 or earlier is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-12-21, and public Akamai research ties it to a Mirai-based botnet campaign exploiting these routers for DDoS activity, with a 50.4% EPSS probability of exploitation over the next 30 days (99th percentile).

Do: Upgrade AE1021 and AE1021PE devices to the latest FXC firmware (any version newer than 2.0.9), per the vendor advisory and the CISA KEV required action; if patching is not possible, discontinue use of the product or restrict its management interface to trusted networks with strong login credentials. Review devices for signs of compromise, such as unexpected outbound connections or changed credentials, since a Mirai-based botnet campaign has been observed exploiting these routers.

8.850% KEV PoC
  • FXC AE1021PE firmware 2.0.9 and earlier
  • FXC AE1021 firmware 2.0.9 and earlier
unknown precise count; plausibly on the order of tens of thousands of deployed units
CVE-2018-0679
Cross-site scripting vulnerability in multiple FXC Inc.

Cross-site scripting vulnerability in multiple FXC Inc. network devices (Managed Ethernet switch FXC5210/5218/5224 firmware prior to version Ver1.00.22, Managed Ethernet switch FXC5426F firmware prior to version Ver1.00.06, Managed Ethernet switch FXC5428 firmware prior to version Ver1.00.07, Power over Ethernet (PoE) switch FXC5210PE/5218PE/5224PE firmware prior to version Ver1.00.14, and Wireless LAN router AE1021/AE1021PE firmware all versions) allows attacker with administrator rights to inject arbitrary web script or HTML via the administrative page.

NVD description · AI analysis pending
4.8<1%
  • fxc fxc5210 firmware
  • fxc fxc5218 firmware
  • fxc fxc5224 firmware
  • +1 more