CVE-2023-31446
10.01.2024, 03:15
In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup.Enginsight
Vendor | Product | Version |
---|---|---|
cassianetworks | xc1000_firmware | 2.1.1.2303082218 |
cassianetworks | xc2000_firmware | 2.1.1.2303090947 |
𝑥
= Vulnerable software versions