CVE-2023-1097

CRITICAL

Baicells EG7035-M11 Firmware <= BCE-ODU-1.0.8 - Unauthenticated Remote Code Execution via HTTP GET Command Injection

Title source: llm
STIX 2.1

Description

Baicells EG7035-M11 devices with firmware through BCE-ODU-1.0.8 are vulnerable to improper code exploitation via HTTP GET command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods have been tested and validated by a 3rd party analyst and have been confirmed exploitable special thanks to Lionel Musonza for the discovery.

Scores

CVSS v3 9.3
EPSS 0.0117
EPSS Percentile 63.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-77 CWE-94
Status published
Products (1)
baicells/eg7035-m11_firmware < bce-odu-1.0.8
Published Mar 01, 2023
Tracked Since Feb 18, 2026