In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 20 Jun 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-77 | |
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-06-20T15:36:04.915Z
Reserved: 2023-04-28T00:00:00.000Z
Link: CVE-2023-31446
Updated: 2024-08-02T14:53:30.768Z
Status : Modified
Published: 2024-01-10T03:15:43.263
Modified: 2025-06-20T16:15:21.150
Link: CVE-2023-31446
No data.
OpenCVE Enrichment
No data.
Weaknesses