Byzoro Vulnerabilities and Affected Products
Vulnerabilities associated with Smart S85F Management Platform.
Products
Clear product- Smart S45F Multi-Service Secure Gateway Intelligent Management Platform9 vulnerabilities
- Smart S85F Management Platform9 vulnerabilities
- S2103 vulnerabilities
- Smart S150 Management Platform3 vulnerabilities
- Smart S802 vulnerabilities
- Smart S80 Management Platform2 vulnerabilities
- smart_s150_firmware2 vulnerabilities
- smart_s802 vulnerabilities
- PatrolFlow 2530Pro1 vulnerability
- Smart S201 vulnerability
- Smart S20 Management Platform1 vulnerability
- Smart S200 Management Platform1 vulnerability
- Smart S210 Management Platform1 vulnerability
- Smart S40 Management Platform1 vulnerability
- Smart S42 Management Platform1 vulnerability
- smart_s1501 vulnerability
- smart_s200_management_platform1 vulnerability
- smart_s20_management_platform1 vulnerability
- smart_s210_firmware1 vulnerability
- smart_s45f1 vulnerability
- smart_s85f_firmware1 vulnerability
- smart_s85f_management_platform1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2023-5959MEDIUM | Byzoro Smart S85F Management Platform login.php password recoveryA vulnerability, which was classified as problematic, was found in Byzoro Smart S85F Management Platform V31R02B10-01. Affected is an unknown function of the file /login.php. The manipulation of the argument txt_newpwd leads to weak password recovery. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-244992. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. CWE-640Nov 11, 2023 | CVSS4.3v3.1 | EPSS0.877% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-5684MEDIUM | Byzoro Smart S85F Management Platform importexport.php os command injectionA vulnerability was found in Byzoro Smart S85F Management Platform up to 20231012. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /importexport.php. The manipulation leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243061 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in an… CWE-78Oct 21, 2023 | CVSS4.7v3.1 | EPSS78.4% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-5683MEDIUM | Byzoro Smart S85F Management Platform importconf.php os command injectionA vulnerability was found in Byzoro Smart S85F Management Platform up to 20231010 and classified as critical. This issue affects some unknown processing of the file /sysmanage/importconf.php. The manipulation of the argument btn_file_renew leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-243059. NOTE: The vendor was contacted early about this disclosure but did… CWE-78Oct 21, 2023 | CVSS6.3v3.1 | EPSS18% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4739MEDIUM | Byzoro Smart S85F Management Platform updateos.php unrestricted uploadA vulnerability, which was classified as critical, has been found in Byzoro Smart S85F Management Platform up to 20230820. Affected by this issue is some unknown functionality of the file /sysmanage/updateos.php. The manipulation of the argument 1_file_upload leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-238628. NOTE: The vendor was contacted early about this disclosure … CWE-434Sep 3, 2023 | CVSS6.3v3.1 | EPSS3.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Byzoro Smart S85F Management Platform licence.php access controlA vulnerability was found in Byzoro Smart S85F Management Platform up to 20230816. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /sysmanage/licence.php. The manipulation leads to improper access controls. The exploit has been disclosed to the public and may be used. The identifier VDB-238057 was assigned to this vulnerability. CWE-284Aug 26, 2023 | CVSS3.5v3.1 | EPSS1.14% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-4544MEDIUM | Byzoro Smart S85F Management Platform php.ini direct requestA vulnerability was found in Byzoro Smart S85F Management Platform up to 20230809. It has been rated as problematic. This issue affects some unknown processing of the file /config/php.ini. The manipulation leads to direct request. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-238049 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. CWE-425Aug 26, 2023 | CVSS4.3v3.1 | EPSS1.05% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4414MEDIUM | Byzoro Smart S85F Management Platform decodmail.php command injectionA vulnerability was found in Byzoro Smart S85F Management Platform up to 20230807. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /log/decodmail.php. The manipulation of the argument file leads to command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-237517 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but di… CWE-77Aug 18, 2023 | CVSS6.3v3.1 | EPSS17.8% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4121MEDIUM | Byzoro Smart S85F Management Platform unrestricted uploadA vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722. It has been classified as critical. Affected is an unknown function. The manipulation of the argument file_upload leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-235968. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. CWE-434Aug 3, 2023 | CVSS6.3v3.1 | EPSS2.51% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4120MEDIUM | Byzoro Smart S85F Management Platform importhtml.php command injectionA vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722 and classified as critical. This issue affects some unknown processing of the file importhtml.php. The manipulation of the argument sql leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235967. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. CWE-77Aug 3, 2023 | CVSS6.3v3.1 | EPSS64.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |