CVE-2023-28343 is a critical OS command injection vulnerability affecting Altenergy Power Control Software C1.2.5, specifically within the apsystems energy_communication_unit and its firmware. This flaw allows unauthenticated attackers to execute arbitrary commands remotely by injecting shell metacharacters into the timezone parameter of the index.php/management/set_timezone function. With a CVSS score of 9.8 (Critical) and an EPSS score of 0.94174, the vulnerability poses a severe risk, enabling full compromise of confidentiality, integrity, and availability. While not yet listed in CISA's KEV catalog, public exploit code is available via ExploitDB and Nuclei templates, indicating a high likelihood of exploitation, despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
c1.2.5CPE matchmatch criteria | cpe:2.3:o:apsystems:energy_communication_unit_firmware:c1.2.5:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.