CVE-2023-43477: Telstra Arcadyan LH1000 Firmware
High severity, CVSS 8.8. EPSS: 17.7% chance of exploitation in the next 30 days.
The ping_from parameter of ping_tracerte.cgi in the web UI of Telstra Smart Modem Gen 2 (Arcadyan LH1000), firmware versions < 0.18.15r, was not properly sanitized before being used in a system call, which could allow an authenticated attacker to achieve command injection as root on the device.
Affected products
- Telstra Arcadyan LH1000 Firmware: before 0.18.15r (fixed in 0.18.15r)
Published 2023-09-20. Last modified 2026-06-17.