Vulnerability record · CVE-2023-26802 · published 26 March 2023
CVE-2023-26802: DCN DCBI-Netlog-LAB cgi auth bypass and command execution
Dcnglobal · Dcbi Netlog Lab Firmware
The /network_config/nsg_masq.cgi component in DCN DCBI-Netlog-LAB v1.0 mishandles input, allowing authentication bypass and arbitrary command execution. The flaw is remotely reachable without credentials, so any exposed instance is at immediate risk.
Description
An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass authentication and execute arbitrary commands via a crafted request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote command execution with a 9.8 CVSS score and high EPSS probability makes this an urgent exposure.
What it is
The /network_config/nsg_masq.cgi component in DCN DCBI-Netlog-LAB v1.0 mishandles input, allowing authentication bypass and arbitrary command execution. The flaw is remotely reachable without credentials, so any exposed instance is at immediate risk.
Impact
An unauthenticated attacker can run arbitrary commands on the device, gaining full control of confidentiality, integrity and availability.
Attack surface
Reached over the network via a crafted HTTP request to /network_config/nsg_masq.cgi; the CVSS vector shows no privileges or user interaction required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.4871 (98.8th percentile) and the only references are public exploit write-ups, indicating exploit code is available.
What to do
- Apply the vendor fix for DCBI-Netlog-LAB v1.0 or upgrade to a patched release if one exists.
- Restrict network access to the management interface and /network_config/ endpoints to trusted hosts only.
- Place the device behind a firewall or VPN; never expose it directly to the internet.
- Monitor and review the referenced public exploit write-up to understand the exact request pattern and block it.
- If no patch is available, isolate the device on a segmented management VLAN.
Detection
- Alert on HTTP requests to /network_config/nsg_masq.cgi, especially with shell metacharacters or traversal sequences.
- Monitor device logs and outbound traffic for unexpected command execution or reverse shells.
- Baseline normal management traffic and flag new source IPs reaching the CGI endpoint.
- Check for unauthorized configuration changes or new accounts on the device.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/winmt/my-vuls/tree/main/DCN%20DCBI-Netlog-LAB | ExploitThird Party Advisory |
| https://github.com/winmt/my-vuls/tree/main/DCN%20DCBI-Netlog-LAB | ExploitThird Party Advisory |
Track CVE-2023-26802 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-26802), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.