Vulnerability record · CVE-2023-4120 · published 3 August 2023
CVE-2023-4120: Byzoro Smart S85F importhtml.php sql argument command injection
BByzoro · Smart S85f
Byzoro Smart S85F Management Platform (up to 20230722) mishandles the sql argument in importhtml.php, allowing command injection. The flaw is rated critical and a public exploit exists, so unpatched management interfaces are at immediate risk. The vendor was contacted but did not respond, so no official fix is confirmed in the record.
Description
A vulnerability was found in Byzoro Smart S85F Management Platform up to 20230722 and classified as critical. This issue affects some unknown processing of the file importhtml.php. The manipulation of the argument sql leads to command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-235967. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or interaction required, a public exploit, and very high EPSS make this an urgent exposure for any internet- or network-reachable Smart S85F.
What it is
Byzoro Smart S85F Management Platform (up to 20230722) mishandles the sql argument in importhtml.php, allowing command injection. The flaw is rated critical and a public exploit exists, so unpatched management interfaces are at immediate risk. The vendor was contacted but did not respond, so no official fix is confirmed in the record.
Impact
An unauthenticated remote attacker can execute arbitrary commands on the device, gaining full control of confidentiality, integrity and availability. This can lead to management-platform takeover and use of the appliance as a pivot into the network.
Attack surface
Reachable over the network via the importhtml.php endpoint with a crafted sql argument; the CVSS vector shows no privileges or user interaction required. The description confirms the attack may be initiated remotely.
Exploitation
A public exploit is referenced (Exploit tag) and the record states the exploit has been disclosed and may be used. The CVE is not in CISA KEV, but EPSS is high at roughly 0.62 (99th percentile), indicating elevated likelihood of exploitation.
What to do
- Apply any vendor patch or firmware update for Smart S85F if one becomes available; the record notes the vendor did not respond, so verify directly with Byzoro.
- If no fix exists, isolate the management interface from untrusted networks and restrict access to a dedicated management VLAN or allowlist.
- Disable or block external access to importhtml.php and other management endpoints at the perimeter until patched.
- Monitor vendor advisories and VDB-235967 for updated remediation guidance.
- Treat the device as compromised if exploitation is suspected and rotate credentials and keys stored on or managed by it.
Detection
- Inspect web and proxy logs for requests to importhtml.php with suspicious sql parameter values containing shell metacharacters.
- Alert on unexpected outbound connections or process execution from the management appliance.
- Monitor for command-injection payload patterns in HTTP parameters reaching the management platform.
- Review authentication and access logs for anomalous access to the management interface from untrusted sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/RCEraser/cve/blob/main/rce.md | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.235967 | Permissions RequiredThird Party AdvisoryVDB Entry |
| https://vuldb.com/?id.235967 | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.185751 | |
| https://github.com/RCEraser/cve/blob/main/rce.md | ExploitThird Party Advisory |
| https://vuldb.com/?ctiid.235967 | Permissions RequiredThird Party AdvisoryVDB Entry |
| https://vuldb.com/?id.235967 | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.185751 |
Track CVE-2023-4120 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-4120), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.