← Vulnerability feed

Vulnerability record · CVE-2023-27521 · published 23 May 2023

CVE-2023-27521: Contec sv-cpt-mc310f firmware os command injection vulnerability

Contec · Sv Cpt Mc310f Firmware

OS command injection vulnerability in the mail setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows remote authenticated attackers to execute an arbitrary OS command.

8.8 CVSS 3.1 High EPSS 1.9% · top 21.1% CWE-78 · OS command injection
8.8CVSS 3.1 base score
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

OS command injection vulnerability in the mail setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows remote authenticated attackers to execute an arbitrary OS command.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-27521 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-29303SolarView Compact conf_mail.php OS command injectionSolarView Compact version 6.00 contains an OS command injection flaw reached through conf_mail.php. An unauthenticated remote attacker can inject and…KEVEPSS 98%analysed9.8CVE-2022-31374Contec sv-cpt-mc310 firmware unrestricted file upload vulnerabilityAn arbitrary file upload vulnerability /images/background/1.php in of SolarView Compact 6.0 allows attackers to execute arbitrary code via a crafted …EPSS 2.4%9.8CVE-2021-20658Contec sv-cpt-mc310 firmware os command injection vulnerabilitySolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an attacker to execute arbitrary OS commands with the web server privilege via unspecified vec…EPSS 3.7%8.8CVE-2023-27514Contec sv-cpt-mc310f firmware os command injection vulnerabilityOS command injection vulnerability in the download page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior…EPSS 1.9%8.8CVE-2023-27518Contec sv-cpt-mc310f firmware classic buffer overflow vulnerabilityBuffer overflow vulnerability in the multiple setting pages of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions p…EPSS 1.5%8.8CVE-2022-35239Contec sv-cpt-mc310f firmware improper input validation vulnerabilityThe image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an insufficien…EPSS 1.4%8.8CVE-2021-20659Contec sv-cpt-mc310 firmware unrestricted file upload vulnerabilitySolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows an authenticated attacker to upload arbitrary files via unspecified vectors. If the file is PH…EPSS 2.1%8.1CVE-2021-20661Contec sv-cpt-mc310 firmware path traversal vulnerabilityDirectory traversal vulnerability in SolarView Compact SV-CPT-MC310 prior to Ver.6.5 allows authenticated attackers to delete arbitrary files and/or …EPSS 2.5%

Source: NIST National Vulnerability Database (record CVE-2023-27521), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.