← Vulnerability feed

Vulnerability record · CVE-2023-45465 · published 13 October 2023

CVE-2023-45465: Netis-systems n3m firmware command injection vulnerability

Netis Systems · N3m Firmware

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ddnsDomainName parameter in the Dynamic DNS settings.

9.8 CVSS 3.1 Critical EPSS 1.8% · top 21.8% CWE-77 · Command injection
9.8CVSS 3.1 base score
1.8%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Netis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ddnsDomainName parameter in the Dynamic DNS settings.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-45465 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-45467Netis-systems n3m firmware os command injection vulnerabilityNetis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the ntpServIP parameter in the Time Settings.EPSS 1.9%9.8CVE-2023-43892Netis-systems n3m firmware os command injection vulnerabilityNetis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the Hostname parameter within the WAN settings. This vulnerabi…EPSS 1.9%9.8CVE-2023-43893Netis-systems n3m firmware os command injection vulnerabilityNetis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability via the wakeup_mac parameter in the Wake-On-LAN (WoL) function. Th…EPSS 1.9%9.8CVE-2023-43891Netis-systems n3m firmware command injection vulnerabilityNetis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the Changing Username and Password function. This vulnerability…EPSS 1.9%8.8CVE-2023-43890Netis-systems n3m firmware os command injection vulnerabilityNetis N3Mv2-V1.0.1.865 was discovered to contain a command injection vulnerability in the diagnostic tools page. This vulnerability is exploited via …EPSS 2.5%7.5CVE-2023-45464Netis-systems n3m firmware classic buffer overflow vulnerabilityNetis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the servDomain parameter. This vulnerability allows attackers to cause a Denia…EPSS 0.62%7.5CVE-2023-45468Netis-systems n3m firmware classic buffer overflow vulnerabilityNetis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the pingWdogIp. This vulnerability allows attackers to cause a Denial of Servi…EPSS 0.68%7.5CVE-2023-45463Netis-systems n3m firmware classic buffer overflow vulnerabilityNetis N3Mv2-V1.0.1.865 was discovered to contain a buffer overflow via the hostName parameter in the FUN_0040dabc function. This vulnerability allows…EPSS 0.62%

Source: NIST National Vulnerability Database (record CVE-2023-45465), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.