blog.csdn.netTechnical descriptionexploit
https://blog.csdn.net/zkaqlaoniao/article/details/134328873 CVE-2023-7311
CRITICAL
BYTEVALUE Intelligent Flow Control Router Command Injection
Record summary
CVE-2023-7311 has a selected CVSS score of 9.3 (critical).
Description
BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is not properly validated and is echoed into a shell context, allowing an attacker to inject and execute arbitrary shell commands on the device. Successful exploitation can lead to writing backdoors, privilege escalation on the host, and full compromise of the router and its management functions. VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Feb 12, 2024 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 15, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Intelligent Flow Control RouterBrowse BYTEVALUE / Intelligent Flow Control Router | VulnCheck | Version data not supplied | |
Flow Control RouterBrowse BYTEVALUE (Luoyang Baiwei Intelligent Technology Co., Ltd.) / Flow Control RouterDefault status: unaffected | CVE List | * | affected |
References
5github.comexploit
https://github.com/adysec/nuclei_poc/blob/49c283b2bbb244c071786a2b768fbdde1b91f38e/poc/web/bytevalue_goform_webread_open_rce.yaml isc.sans.eduTechnical descriptionexploit
https://isc.sans.edu/diary/Exploit+against+Unnamed+Bytevalue+router+vulnerability+included+in+Mirai+Bot/30642 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-7311 vulncheck.comThird-party advisory
https://www.vulncheck.com/advisories/bytevalue-intelligent-flow-control-router-command-injection