CVE-2023-24709

HIGH

Paradox Security Systems IPR512 - DoS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2023-24709. PoCs published by Giorgi Dograshvili, DRAGOWN.

AI-analyzed exploit summary This script exploits a Denial of Service (DoS) vulnerability in Paradox Security Systems IPR512 by sending a malformed HTTP GET request to the login.cgi endpoint. The exploit uses a crafted payload in the log_user parameter to trigger the vulnerability.

Description

An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and login.xml parameters.

Exploits (2)

exploitdb WORKING POC
by Giorgi Dograshvili · bashdoshardware
https://www.exploit-db.com/exploits/51356

This script exploits a Denial of Service (DoS) vulnerability in Paradox Security Systems IPR512 by sending a malformed HTTP GET request to the login.cgi endpoint. The exploit uses a crafted payload in the log_user parameter to trigger the vulnerability.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Paradox Security Systems IPR512
No auth needed
Prerequisites: Network access to the target device · Target device must be running the vulnerable IPR512 firmware
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 2 stars
by DRAGOWN · poc
https://github.com/DRAGOWN/CVE-2023-24709-PoC

This repository contains a functional PoC for CVE-2023-24709, an unauthenticated JavaScript injection vulnerability in Paradox Security Systems IPR512. The exploit overwrites the 'login.xml' file, causing the login form to crash and become unavailable.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Paradox Security Systems IPR512
No auth needed
Prerequisites: Access to the target IPR512 web panel
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Scores

CVSS v3 7.5
EPSS 0.3498
EPSS Percentile 97.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-94
Status published
Products (1)
paradox/ipr512_firmware
Published Mar 21, 2023
Tracked Since Feb 18, 2026