← back
CVE-2023-20820

CVE-2023-20820

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 1.2%
exploitation probability
1.2%top 35% of all CVEs
observed exploitation
nono source reports it
In short

A wireless network service fails to properly check user input before running commands, allowing attackers to inject malicious commands and execute code remotely without needing any interaction from the user.

Technical detail

The wlan service contains an improper input validation vulnerability in command processing that allows unauthenticated remote code injection. Exploitation requires System-level privileges for execution and can be triggered automatically without user interaction.

Summary generated and translated by AI from the official description.
In wlan service, there is a possible command injection due to improper input validation. This could lead to remote code execution with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: WCNCR00244189; Issue ID: WCNCR00244189.