← Vulnerability feed

Vulnerability record · CVE-2023-5885 · published 27 November 2023

CVE-2023-5885: Franklinfueling colibri firmware path traversal vulnerability

Franklinfueling · Colibri Firmware

The discontinued FFS Colibri product allows a remote user to access files on the system including files containing login credentials for other users.

6.5 CVSS 3.1 Medium EPSS 1.1% · top 35.6% CWE-35 · CWE-35CWE-22 · Path traversal
6.5CVSS 3.1 base score
1.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The discontinued FFS Colibri product allows a remote user to access files on the system including files containing login credentials for other users.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-5885 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-44039Franklinfueling colibri firmware incorrect authorization vulnerabilityFranklin Fueling System FFS Colibri 1.9.22.8925 is affected by: File system overwrite. The impact is: File system rewrite (remote). ¶¶ An attacker ca…EPSS 1.0%7.5CVE-2021-46417Franklin Fueling Colibri Controller path traversal in download functionThe Colibri Controller Module 1.8.19.8580 handles a download function insecurely, allowing path traversal that discloses internal files. Because the …EPSS 60%analysed9.4CVE-2025-62593Ray browser-based RCE via insufficient User-Agent guardRay, an AI compute engine, contains a critical remote code execution flaw before version 2.52.0. Its defense against browser-based attacks relies on …KEVEPSS 62%analysed8.1CVE-2008-4128Cisco IOS HTTP Administration CSRF allows arbitrary command executionThe HTTP Administration component in Cisco IOS 12.4 on the 871 Integrated Services Router is vulnerable to multiple cross-site request forgery flaws.…KEVEPSS 34%analysed8.4CVE-2025-8088WinRAR path traversal lets crafted archives execute codeCVE-2025-8088 is a path traversal flaw in the Windows version of WinRAR that allows attackers to execute arbitrary code by crafting malicious archive…KEVEPSS 94%analysed8.8CVE-2023-2533PaperCut NG/MF CSRF allows admin security setting changes and code executionPaperCut NG and MF contain a cross-site request forgery flaw that, under specific conditions, lets an attacker change security settings or execute ar…KEVEPSS 29%analysed8.8CVE-2024-7965Google Chrome V8 inappropriate implementation allows heap corruptionGoogle Chrome before 128.0.6613.84 contains an inappropriate implementation in the V8 JavaScript engine that can lead to heap corruption. The flaw is…KEVEPSS 19%analysed8.0CVE-2014-100005D-Link DIR-600 router CSRF enables admin account creation and remote managementThe D-Link DIR-600 (rev. Bx) with firmware before 2.17b02 is affected by multiple cross-site request forgery flaws in hedwig.cgi, pigwidgeon.cgi and …KEVEPSS 43%analysed

Source: NIST National Vulnerability Database (record CVE-2023-5885), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.