CVE-2023-5494 is a critical OS command injection vulnerability affecting Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to version 20230928. This flaw allows a remote attacker to execute arbitrary commands by manipulating the 'file' argument in the /log/download.php file. With a CVSS score of 8.8 (High), the vulnerability is easily exploitable over the network with low privileges, leading to high impact on confidentiality, integrity, and availability. Although the exploit has been publicly disclosed, there is no evidence of active exploitation, and it lacks community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 20230928CPE matchmatch criteria | cpe:2.3:o:byzoro:smart_s45f_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.