← Vulnerability feed

Vulnerability record · CVE-2023-29711 · published 22 June 2023

CVE-2023-29711: Interlink PSG-5124 access control flaw allows remote code execution

Interlink · Psg 5124 Firmware

Interlink PSG-5124 firmware version 1.0.4 has an incorrect access control issue that lets attackers execute arbitrary code through a crafted GET request. The flaw is remotely reachable without authentication, so any exposed device is at risk of full compromise.

9.8 CVSS 3.1 Critical EPSS 70% · top 0.6% CWE-346 · Origin validation error
9.8CVSS 3.1 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An incorrect access control issue was discovered in Interlink PSG-5124 version 1.0.4, allows attackers to execute arbitrary code via crafted GET request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or user interaction required and public exploit references make this a critical remote code execution risk.

What it is

Interlink PSG-5124 firmware version 1.0.4 has an incorrect access control issue that lets attackers execute arbitrary code through a crafted GET request. The flaw is remotely reachable without authentication, so any exposed device is at risk of full compromise.

Impact

An unauthenticated attacker can run arbitrary code on the device, gaining full control of confidentiality, integrity and availability. This can lead to device takeover and use as a foothold into the network.

Attack surface

The vulnerability is reached over the network via a crafted HTTP GET request, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication or user interaction is required.

Exploitation

CISA KEV does not list this CVE, but public exploit references are tagged Exploit and EPSS is 0.70308 (99.35th percentile), indicating a high likelihood of exploitation activity.

What to do

  • Apply the vendor patch for PSG-5124 firmware 1.0.4 or later if available; if no patch exists, isolate or replace the device.
  • Remove direct internet exposure of the PSG-5124 management interface and restrict access to trusted management networks.
  • Enforce authentication and network access controls in front of the device where possible.
  • Monitor vendor advisories for updated firmware and remediation guidance.

Detection

  • Inspect HTTP logs for crafted GET requests targeting the PSG-5124 management interface.
  • Alert on unexpected outbound connections or command execution behavior from PSG-5124 devices.
  • Baseline normal device traffic and flag anomalous requests to the switch management endpoint.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-29711 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2023-29711), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.