← volver
CVE-2023-7311criticalexplotación observadaCWE-78

BYTEVALUE Intelligent Flow Control Router Command Injection

70Vexday Risk Score

Prioriza la corrección. Ella explotación observada por VulnCheck y tiene prueba de concepto pública.

ssvc Actcvss 9.3epss 1.9%
de la publicación al arma
Publicada en NVD15 oct
VulnCheck12 feb
probabilidad de explotación
1.9%top 22% de las CVE
explotación observada
VulnCheck
3 exploit(s) público(s)
BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is not properly validated and is echoed into a shell context, allowing an attacker to inject and execute arbitrary shell commands on the device. Successful exploitation can lead to writing backdoors, privilege escalation on the host, and full compromise of the router and its management functions. VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.