S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jun 15, 2025

CVE-2023-26802 Scanner

CVE-2023-26802 Scanner - Command Injection vulnerability in DCN DCBI-Netlog-LAB

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-26802
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

An issue in the component /network_config/nsg_masq.cgi of DCN (Digital China Networks) DCBI-Netlog-LAB v1.0 allows attackers to bypass authentication and execute arbitrary commands via a crafted request.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 19, 2026View on NVD →
Detail

DCN DCBI-Netlog-LAB is used by network administrators for configuring network settings and managing security protocols. It is designed to facilitate secure network operations and enhance the efficiency of network management. The software is commonly utilized by medium to large enterprises to streamline network administration tasks. It integrates seamlessly with existing infrastructure, supporting scalability and robust security measures. Organizations rely on this product to ensure network reliability and integrity. Given its comprehensive features, it is a critical component in the network management toolkit of many IT professionals.

Command Injection is a critical vulnerability where an attacker can inject arbitrary commands into a program, allowing unauthorized execution of commands. This specific vulnerability in DCN DCBI-Netlog-LAB v1.0 allows attackers to bypass authentication and exploit the network configuration component. Once exploited, it provides unauthorized command execution capabilities on the server. This flaw is especially concerning due to its remote access potential, requiring no prior authentication. The injection can be executed via specially crafted requests that manipulate system commands. Command Injection compromises the security and reliability of the affected systems.

The vulnerability resides in the network configuration endpoint /network_config/nsg_masq.cgi of the DCN DCBI-Netlog-LAB. Attackers can manipulate parameters such as user_name and session_id to inject commands. The crafted request enables attackers to execute arbitrary commands, utilizing the HTTP GET method. By crafting a specific request payload, attackers exploit the command injection flaw without needing authentication. This can lead to manipulation of the system by appending shell commands to HTTP parameters. The vulnerability affects all instances running version 1.0 of the product.

When exploited, this Command Injection vulnerability can lead to unauthorized command execution on the server, potentially resulting in system compromise. Attackers may gain control over the affected system, leading to data breaches and unauthorized access to sensitive information. Additionally, it might allow the attacker to escalate privileges, pivot within the network, and deploy further payloads. The integrity, confidentiality, and availability of the affected systems are at significant risk. Organizations could face operational disruptions, financial losses, and reputational damage due to this vulnerability.

Solution Advice
  • Update DCN DCBI-Netlog-LAB to the latest version where this vulnerability is patched.
  • Implement input validation to filter out malicious command strings at critical endpoints.
  • Restrict access to network configuration components to authorized personnel only.
  • Use Web Application Firewalls (WAF) to detect and block malicious requests.
  • Conduct regular security audits and vulnerability assessments to identify and mitigate potential security issues.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-26802 Scanner - Command Injection vulnerability in DCN DCBI-Netlog-LAB S4E