Skip to content

Known CVE

Cassia Gateway Firmware - Remote Code Execution

In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup.

CVE-2023-31446

Critical2023CVSS 9.8

cve2023 · rce · cassia · gateway · cassianetworks · vkev · vuln

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website