← Vulnerability feed

Vulnerability record · CVE-2023-4120 · published 3 August 2023

CVE-2023-4120: Byzoro Smart S85F importhtml.php sql argument command injection

BByzoro · Smart S85f

Byzoro Smart S85F Management Platform (up to 20230722) mishandles the sql argument in importhtml.php, allowing command injection. The flaw is rated critical and a public exploit exists, so unpatched management interfaces are at immediate risk. The vendor was contacted but did not respond, so no official fix is confirmed in the record.

9.8 CVSS 3.1 Critical EPSS 62% · top 0.8% CWE-77 · Command injection
9.8CVSS 3.1 base score, v2 6.5
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722 and classified as critical. This issue affects some unknown processing of the file importhtml.php. The manipulation of the argument sql leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235967. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with no authentication or interaction required, a public exploit, and very high EPSS make this an urgent exposure for any internet- or network-reachable Smart S85F.

What it is

Byzoro Smart S85F Management Platform (up to 20230722) mishandles the sql argument in importhtml.php, allowing command injection. The flaw is rated critical and a public exploit exists, so unpatched management interfaces are at immediate risk. The vendor was contacted but did not respond, so no official fix is confirmed in the record.

Impact

An unauthenticated remote attacker can execute arbitrary commands on the device, gaining full control of confidentiality, integrity and availability. This can lead to management-platform takeover and use of the appliance as a pivot into the network.

Attack surface

Reachable over the network via the importhtml.php endpoint with a crafted sql argument; the CVSS vector shows no privileges or user interaction required. The description confirms the attack may be initiated remotely.

Exploitation

A public exploit is referenced (Exploit tag) and the record states the exploit has been disclosed and may be used. The CVE is not in CISA KEV, but EPSS is high at roughly 0.62 (99th percentile), indicating elevated likelihood of exploitation.

What to do

  • Apply any vendor patch or firmware update for Smart S85F if one becomes available; the record notes the vendor did not respond, so verify directly with Byzoro.
  • If no fix exists, isolate the management interface from untrusted networks and restrict access to a dedicated management VLAN or allowlist.
  • Disable or block external access to importhtml.php and other management endpoints at the perimeter until patched.
  • Monitor vendor advisories and VDB-235967 for updated remediation guidance.
  • Treat the device as compromised if exploitation is suspected and rotate credentials and keys stored on or managed by it.

Detection

  • Inspect web and proxy logs for requests to importhtml.php with suspicious sql parameter values containing shell metacharacters.
  • Alert on unexpected outbound connections or process execution from the management appliance.
  • Monitor for command-injection payload patterns in HTTP parameters reaching the management platform.
  • Review authentication and access logs for anomalous access to the management interface from untrusted sources.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/RCEraser/cve/blob/main/rce.md ExploitThird Party Advisory
https://vuldb.com/?ctiid.235967 Permissions RequiredThird Party AdvisoryVDB Entry
https://vuldb.com/?id.235967 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.185751
https://github.com/RCEraser/cve/blob/main/rce.md ExploitThird Party Advisory
https://vuldb.com/?ctiid.235967 Permissions RequiredThird Party AdvisoryVDB Entry
https://vuldb.com/?id.235967 Third Party AdvisoryVDB Entry
https://vuldb.com/?submit.185751

Track CVE-2023-4120 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-4414Byzoro smart s85f command injection vulnerabilityA vulnerability was found in Byzoro Smart S85F Management Platform up to 20230807. It has been declared as critical. Affected by this vulnerability i…EPSS 9.1%9.8CVE-2023-4121Byzoro smart s85f unrestricted file upload vulnerabilityA vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722. It has been classified as critical. Affected is an unknown functio…EPSS 2.5%9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed8.7CVE-2026-42271LiteLLM MCP test endpoints allow authenticated OS command injectionLiteLLM versions 1.74.2 through before 1.83.7 expose two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) th…KEVEPSS 13%analysed7.2CVE-2025-29635D-Link DIR-823X command injection in set_prohibiting handlerD-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already h…KEVEPSS 88%analysed8.1CVE-2026-22719VMware Aria Operations command injection during support-assisted migrationVMware Aria Operations contains a command injection flaw (CWE-77) that an unauthenticated attacker can use to run arbitrary commands, potentially ach…KEVEPSS 18%analysed8.7CVE-2025-4008Meteobridge web interface command injection without authenticationThe Meteobridge web interface, built from CGI shell scripts and C, exposes an endpoint vulnerable to command injection. Because the endpoint also lac…KEVEPSS 94%analysed6.1CVE-2025-59689Libraesva ESG command injection via compressed email attachmentLibraesva Email Security Gateway versions 4.5 through 5.5.x before 5.5.7 are vulnerable to command injection triggered by a compressed email attachme…KEVEPSS 1.9%analysed

Source: NIST National Vulnerability Database (record CVE-2023-4120), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.