Byzoro manufactures a line of specialized storage and security appliances, including the SMART S45F, S85F, and S210 series, that serve as critical infrastructure components in network environments. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and recur through a consistent set of weakness classes spanning file-upload validation, OS command injection, SQL injection, and access-control flaws that are typical of management interfaces and administrative functions in embedded appliances. The concentration of high-severity issues across this focused product portfolio reflects the intersection of administrative privilege levels, backend system integration, and the parsing demands of appliance configuration and monitoring. Defenders should treat Byzoro advisories as high-priority and conduct thorough inventory of affected appliances in their network perimeter; live exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Byzoro over time
Signals from CVEs in this vendor scope (31 CVEs).
31 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-4120CRITICAL A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722 and classified as critical. This issue affects some unknown processing of the file importhtml.php. | Aug 3, 2023 | 9.8 | 75 | NO | NO |
CVE-2023-4873CRITICAL A vulnerability, which was classified as critical, was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230906. Affected is an unknow | Sep 10, 2023 | 9.8 | 73 | NO | NO |
CVE-2023-5684CRITICAL A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231012. It has been declared as critical. Affected by this vulnerability is an unknown functionality of t | Oct 21, 2023 | 9.8 | 70 | NO | NO |
CVE-2024-0939CRITICAL A vulnerability has been found in Byzoro Smart S210 Management Platform up to 20240117 and classified as critical. This vulnerability affects unknown code of the file /Tool/uploadf | Jan 26, 2024 | 9.8 | 62 | NO | YES |
CVE-2023-5683CRITICAL A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231010 and classified as critical. This issue affects some unknown processing of the file /sysmanage/impo | Oct 21, 2023 | 9.8 | 37 | NO | NO |
CVE-2023-7039CRITICAL A vulnerability classified as critical has been found in Byzoro S210 up to 20231210. Affected is an unknown function of the file /importexport.php. The manipulation of the argument | Dec 21, 2023 | 9.8 | 36 | NO | NO |
CVE-2023-4414CRITICAL A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230807. It has been declared as critical. Affected by this vulnerability is an unknown functionality of t | Aug 18, 2023 | 9.8 | 36 | NO | NO |
CVE-2024-0300CRITICAL A vulnerability was found in Byzoro Smart S150 Management Platform up to 20240101. It has been rated as critical. Affected by this issue is some unknown functionality of the file / | Jan 8, 2024 | 9.8 | 30 | NO | NO |
CVE-2023-5494HIGH A vulnerability was found in Byzoro Smart S45F Multi-Service Secure Gateway Intelligent Management Platform up to 20230928 and classified as critical. Affected by this issue is som | Oct 10, 2023 | 8.8 | 30 | NO | NO |
CVE-2023-4121CRITICAL A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722. It has been classified as critical. Affected is an unknown function. The manipulation of the argu | Aug 3, 2023 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (31 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Byzoro.
Media articles that mention a CVE ID that affects a product developed by Byzoro — matched by CVE ID, not by vendor name.