Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2023-31446

In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.917
EPSS Ranking 99.7%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2023-31446


Contact Us

Shodan ® - All rights reserved