← Vulnerability feed

Vulnerability record · CVE-2023-29919 · published 23 May 2023

CVE-2023-29919: SolarView Compact texteditor.php insecure permissions allow arbitrary file read and write

Contec · Solarview Compact Firmware

SolarView Compact firmware version 6.0 and earlier exposes texteditor.php without proper permission restrictions, letting any file on the server be read or modified. Because the endpoint is reachable over the network with no authentication, an attacker can tamper with firmware or configuration files or exfiltrate sensitive data. The flaw is a CWE-276 incorrect default permissions issue.

9.1 CVSS 3.1 Critical EPSS 60% · top 0.9% CWE-276 · Incorrect default permissions
9.1CVSS 3.1 base score
60%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

critical priorityCVSS 9.1 with no authentication or user interaction required, a public exploit, and very high EPSS make this an urgent exposure for internet-reachable SolarView Compact devices.

What it is

SolarView Compact firmware version 6.0 and earlier exposes texteditor.php without proper permission restrictions, letting any file on the server be read or modified. Because the endpoint is reachable over the network with no authentication, an attacker can tamper with firmware or configuration files or exfiltrate sensitive data. The flaw is a CWE-276 incorrect default permissions issue.

Impact

An attacker gains full read and write access to arbitrary files on the device, enabling configuration tampering, credential or data theft, and potential code execution through modified files. Integrity and confidentiality are both fully compromised; availability is not directly affected per the CVSS vector.

Attack surface

Reachable over the network via HTTP through texteditor.php; the CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required. Any host that can reach the device's web interface can attempt exploitation.

Exploitation

A public exploit reference exists on GitHub, and EPSS is 0.60 (99th percentile), indicating high likelihood of exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is documented in this record.

What to do

  • Apply the vendor's patched firmware for SolarView Compact if available; version 6.0 and earlier are affected.
  • Restrict network access to the device web interface using firewall rules or VLAN segmentation so only trusted management hosts can reach it.
  • Disable or remove texteditor.php if it is not required for operations.
  • Enforce authentication and authorization on all administrative endpoints and audit file permissions on the device.
  • Monitor the device for unauthorized file changes and replace end-of-life units that no longer receive firmware updates.

Detection

  • Monitor HTTP requests to texteditor.php, especially POST or PUT requests with file path parameters, in web server or proxy logs.
  • Alert on unexpected changes to configuration or firmware files on SolarView Compact devices via file integrity monitoring.
  • Watch for outbound connections or data transfers from the device to unknown hosts that could indicate file exfiltration.
  • Correlate access to texteditor.php from IP addresses outside the normal management network.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/xiaosed/CVE-2023-29919/ ExploitThird Party Advisory
https://www.solarview.io/ Not Applicable
https://github.com/xiaosed/CVE-2023-29919/ ExploitThird Party Advisory
https://www.solarview.io/ Not Applicable

Track CVE-2023-29919 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-46509Contec solarview compact firmware code injection vulnerabilityAn issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.EPSS 0.81%9.8CVE-2023-23333SolarView Compact downloader.php command injectionSolarView Compact firmware through version 6.00 contains a command injection flaw in downloader.php that lets attackers bypass internal restrictions …EPSS 99%analysed9.8CVE-2022-44354Contec solarview compact firmware unrestricted file upload vulnerabilitySolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.EPSS 1.5%9.8CVE-2022-40881Contec solarview compact firmware command injection vulnerabilitySolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.phpEPSS 30%7.5CVE-2023-40924Contec solarview compact firmware path traversal vulnerabilitySolarView Compact < 6.00 is vulnerable to Directory Traversal.EPSS 3.2%6.1CVE-2022-44355Contec solarview compact firmware cross-site scripting vulnerabilitySolarView Compact 7.0 is vulnerable to Cross-site Scripting (XSS) via /network_test.php.EPSS 1.7%7.8CVE-2026-87886Acronis Backup plugins for cPanel, Plesk and DirectAdmin local privilege escalationAcronis Backup plugins for cPanel & WHM, Plesk and DirectAdmin on Linux ship with insecure file permissions (CWE-276), allowing a local user to escal…KEVEPSS 0.23%analysed6.5CVE-2022-22948VMware vCenter Server information disclosure via incorrect file permissionsvCenter Server ships files with incorrect default permissions, allowing a user with non-administrative access to read sensitive information. Because …KEVEPSS 13%analysed

Source: NIST National Vulnerability Database (record CVE-2023-29919), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.