← Vulnerability feed

Vulnerability record · CVE-2023-44860 · published 6 October 2023

CVE-2023-44860: Netis-systems n3m firmware incorrect authorization vulnerability

Netis Systems · N3m Firmware

An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization component in the HTTP request.

7.5 CVSS 3.1 High EPSS 20% · top 2.7% CWE-863 · Incorrect authorization
7.5CVSS 3.1 base score
20%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An issue in NETIS SYSTEMS N3Mv2 v.1.0.1.865 allows a remote attacker to cause a denial of service via the authorization component in the HTTP request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-44860 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-45465Netis-systems n3m firmware command injection vulnerabilityNetis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ddnsDomainName parameter in the Dynamic DNS settings.EPSS 1.8%9.8CVE-2023-45467Netis-systems n3m firmware os command injection vulnerabilityNetis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ntpServIP parameter in the Time Settings.EPSS 1.9%9.8CVE-2023-43892Netis-systems n3m firmware os command injection vulnerabilityNetis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the WAN settings. This vulnerabi…EPSS 1.9%9.8CVE-2023-43893Netis-systems n3m firmware os command injection vulnerabilityNetis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) function. Th…EPSS 1.9%9.8CVE-2023-43891Netis-systems n3m firmware command injection vulnerabilityNetis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability…EPSS 1.9%8.8CVE-2023-43890Netis-systems n3m firmware os command injection vulnerabilityNetis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the diagnostic tools page. This vulnerability is exploited via …EPSS 2.5%7.5CVE-2023-45464Netis-systems n3m firmware classic buffer overflow vulnerabilityNetis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the servDomain parameter. This vulnerability allows attackers to cause a Denia…EPSS 0.62%7.5CVE-2023-45468Netis-systems n3m firmware classic buffer overflow vulnerabilityNetis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the pingWdogIp. This vulnerability allows attackers to cause a Denial of Servi…EPSS 0.68%

Source: NIST National Vulnerability Database (record CVE-2023-44860), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.