CVE-2023-7311: BYTEVALUE Intelligent Flow Control Router Command Injection
BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The path parameter is not properly validated and is echoed into a shell context, allowing an attacker to inject and execute arbitrary shell commands on the device. Successful exploitation can lead to writing backdoors, privilege escalation on the host, and full compromise of the router and its management functions. VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7311?
CVE-2023-7311 is considered a critical vulnerability due to its potential for remote command execution.
How do I fix CVE-2023-7311?
To fix CVE-2023-7311, update the BYTEVALUE Intelligent Flow Control Router to the latest version that mitigates this command injection vulnerability.
What is the impact of CVE-2023-7311?
The impact of CVE-2023-7311 allows an attacker to execute arbitrary shell commands on the affected BYTEVALUE router.
What should I do if I can't update my BYTEVALUE Intelligent Flow Control Router to fix CVE-2023-7311?
If unable to update, you should restrict access to the device and monitor for suspicious activity to mitigate CVE-2023-7311.
Is CVE-2023-7311 being actively exploited?
Yes, there are reports of CVE-2023-7311 being exploited in the wild, making it crucial to address this vulnerability immediately.