### [CVE-2023-38829](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-38829) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description An issue in NETIS SYSTEMS WF2409E v.3.6.42541 allows a remote attacker to execute arbitrary code via the ping and traceroute functions of the diagnostic tools component in the admin management interface. ### POC #### Reference - https://github.com/adhikara13/CVE-2023-38829-NETIS-WF2409E #### Github - https://github.com/Luwak-IoT-Security/CVEs - https://github.com/adhikara13/CVE-2023-38829-NETIS-WF2409E - https://github.com/nomi-sec/PoC-in-GitHub