CVE-2023-38120

Adtran SR400ac ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adtran SR400ac routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ping command, which is available over JSON-RPC. A crafted host parameter can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-20525.
CVSS

No CVSS.

Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:adtran:sr400ac_firmware:10.8.5.1:*:*:*:*:*:*:*
cpe:2.3:o:adtran:sr400ac_firmware:10.8.8.1:*:*:*:*:*:*:*
cpe:2.3:h:adtran:sr400ac:-:*:*:*:*:*:*:*

History

12 Aug 2025, 15:51

Type Values Removed Values Added
CPE cpe:2.3:o:adtran:sr400ac_firmware:10.8.8.1:*:*:*:*:*:*:*
cpe:2.3:o:adtran:sr400ac_firmware:10.8.5.1:*:*:*:*:*:*:*
cpe:2.3:h:adtran:sr400ac:-:*:*:*:*:*:*:*
CWE CWE-77
References () https://www.zerodayinitiative.com/advisories/ZDI-23-1010/ - () https://www.zerodayinitiative.com/advisories/ZDI-23-1010/ - Third Party Advisory
First Time Adtran
Adtran sr400ac
Adtran sr400ac Firmware

18 Sep 2024, 19:15

Type Values Removed Values Added
Summary Adtran SR400ac ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adtran SR400ac routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ping command, which is available over JSON-RPC. A crafted host parameter can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-20525. Adtran SR400ac ping Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adtran SR400ac routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ping command, which is available over JSON-RPC. A crafted host parameter can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-20525.

03 May 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-03 02:15

Updated : 2025-08-12 15:51


NVD link : CVE-2023-38120

Mitre link : CVE-2023-38120


JSON object : View

Products Affected

adtran

  • sr400ac_firmware
  • sr400ac
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')