← Vulnerability feed

Vulnerability record · CVE-2023-5684 · published 21 October 2023

CVE-2023-5684: Byzoro Smart S85F Management Platform importexport.php OS command injection

BByzoro · Smart S85f Firmware

Byzoro Smart S85F Management Platform (up to 20231012) contains an OS command injection flaw in the /importexport.php file. The vulnerability is rated critical and can be triggered remotely without authentication, allowing arbitrary command execution on the device. The vendor was contacted but did not respond, so no official fix is known.

9.8 CVSS 3.1 Critical EPSS 78% · top 0.4% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 5.8
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability was found in Byzoro Smart S85F Management Platform up to 20231012. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /importexport.php. The manipulation leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-243061 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication required, public exploit code, and very high EPSS make this an urgent risk for any exposed Smart S85F device.

What it is

Byzoro Smart S85F Management Platform (up to 20231012) contains an OS command injection flaw in the /importexport.php file. The vulnerability is rated critical and can be triggered remotely without authentication, allowing arbitrary command execution on the device. The vendor was contacted but did not respond, so no official fix is known.

Impact

An unauthenticated remote attacker can execute arbitrary operating system commands on the management platform, gaining full control of the device with high confidentiality, integrity and availability impact. This could allow configuration tampering, data theft, or use of the device as a pivot into the network.

Attack surface

The flaw is reached over the network via the /importexport.php endpoint of the web management interface. The CVSS vector (AV:N/AC:L/PR:N/UI:N) indicates no authentication and no user interaction are required.

Exploitation

A public exploit has been disclosed (reference tagged Exploit) and EPSS is very high at 0.784 (99.6th percentile), though the CVE is not listed in CISA KEV. No ransomware usage is documented.

What to do

  • Apply any vendor patch or firmware update for Smart S85F if one becomes available; the vendor did not respond to the disclosure, so verify current firmware status directly.
  • Restrict network access to the management interface so /importexport.php is not reachable from untrusted networks; place it behind a firewall or VPN.
  • Disable or block the import/export functionality if it is not required for operations.
  • Monitor and audit the device for unexpected command execution or configuration changes, and consider replacing the device if no fix is forthcoming.

Detection

  • Inspect web server or device logs for requests to /importexport.php, especially with unusual parameters or command-like payloads.
  • Monitor for unexpected outbound connections or process execution on the device that could indicate command injection.
  • Alert on anomalous configuration changes or file imports/exports on the management platform.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-5684 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-5683Byzoro smart s85f firmware os command injection vulnerabilityA vulnerability was found in Byzoro Smart S85F Management Platform up to 20231010 and classified as critical. This issue affects some unknown process…EPSS 18%9.8CVE-2023-4739Byzoro smart s85f firmware unrestricted file upload vulnerabilityA vulnerability, which was classified as critical, has been found in Byzoro Smart S85F Management Platform up to 20230820. Affected by this issue is …EPSS 3.6%4.3CVE-2023-5959Byzoro smart s85f firmware weak password recovery vulnerabilityA vulnerability, which was classified as problematic, was found in Byzoro Smart S85F Management Platform V31R02B10-01. Affected is an unknown functio…EPSS 0.88%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed7.8CVE-2026-83549SonicWall SMA1000 AMC OS Command InjectionThe SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary op…KEVEPSS 11%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed

Source: NIST National Vulnerability Database (record CVE-2023-5684), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.