CVE-2023-0830

MEDIUM

EasyNAS 1.1.0 - OS Command Injection via /backup.pl

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2023-0830. PoCs published by Ivan Spiridonov, xbz0n.

AI-analyzed exploit summary This exploit leverages an OS command injection vulnerability in EasyNas 1.1.0 via the backup.pl endpoint. It authenticates, then injects a base64-encoded reverse shell payload into the 'name' parameter, triggering remote code execution.

Description

A vulnerability classified as critical has been found in EasyNAS 1.1.0. Affected is the function system of the file /backup.pl. The manipulation leads to os command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component.

Exploits (2)

exploitdb WORKING POC
by Ivan Spiridonov · pythonremotehardware
https://www.exploit-db.com/exploits/51266

This exploit leverages an OS command injection vulnerability in EasyNas 1.1.0 via the backup.pl endpoint. It authenticates, then injects a base64-encoded reverse shell payload into the 'name' parameter, triggering remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: EasyNas 1.1.0
Auth required
Prerequisites: Valid credentials for EasyNas · Network access to the target · Listener setup for reverse shell
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by xbz0n · poc
https://github.com/xbz0n/CVE-2023-0830

This is a functional exploit for CVE-2023-0830, targeting a command injection vulnerability in EasyNAS. It includes authentication, command execution via base64-encoded payloads, and an integrated reverse shell listener.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: EasyNAS (version not specified)
Auth required
Prerequisites: Valid credentials for EasyNAS · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.220950
Permissions Required, Third Party Advisory, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.220950
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.86683
Various Sources exploit
https://github.com/xbz0n/CVE-2023-0830
Exploit, Third Party Advisory exploit
https://www.exploit-db.com/exploits/51266

Scores

CVSS v3 6.3
EPSS 0.2086
EPSS Percentile 97.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-77 CWE-78
Status published
Products (1)
easynas/easynas 1.1.0
Published Feb 14, 2023
Tracked Since Feb 18, 2026