CVE-2023-23333 is a critical command injection vulnerability affecting Contec SolarView Compact through version 6.00, allowing unauthenticated attackers to execute arbitrary commands via downloader.php. With a CVSS score of 9.8 (CRITICAL), this flaw requires no user interaction or privileges, making it easily exploitable over the network with full confidentiality, integrity, and availability impact. Exploit code is publicly available through Metasploit and Nuclei, and it has garnered significant community and media attention, with reports of over 130,000 exposed systems, though it is not yet listed on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.00CPE matchmatch criteria | cpe:2.3:o:contec:solarview_compact_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.