cve-2023-7311

CRITICAL CVSS 9.3 opencve
Description

BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is not properly validated and is echoed into a shell context, allowing an attacker to inject and execute arbitrary shell commands on the device. Successful exploitation can lead to writing backdoors, privilege escalation on the host, and full compromise of the router and its management functions. VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.

Timeline
Published
2025-10-15 02:15 UTC
Last Modified
2026-06-17
CVSS Details

CVSS details not available.

Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N mitre
4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X nvd
4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N opencve
References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cve": "CVE-2023-7311",
  "enrichment": {
    "created": "2025-10-21T09:41:16.390214+00:00",
    "updated": "2025-10-21T09:41:16.390238+00:00",
    "vendors": [
      "bytevalue",
      "bytevalue$PRODUCT$flow_control_router"
    ]
  },
  "epss": {
    "score": 0.01858
  },
  "mitre": {
    "cpes": [],
    "created": "2025-10-15T01:19:38.316000+00:00",
    "description": "BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is not properly validated and is echoed into a shell context, allowing an attacker to inject and execute arbitrary shell commands on the device. Successful exploitation can lead to writing backdoors, privilege escalation on the host, and full compromise of the router and its management functions. VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {
        "score": 9.3,
        "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
      }
    },
    "mitre_repo_path": "cves/2023/7xxx/CVE-2023-7311.json",
    "references": [
      "https://blog.csdn.net/zkaqlaoniao/article/details/134328873",
      "https://github.com/adysec/nuclei_poc/blob/49c283b2bbb244c071786a2b768fbdde1b91f38e/poc/web/bytevalue_goform_webread_open_rce.yaml",
      "https://isc.sans.edu/diary/Exploit+against+Unnamed+Bytevalue+router+vulnerability+included+in+Mirai+Bot/30642",
      "https://www.vulncheck.com/advisories/bytevalue-intelligent-flow-control-router-command-injection"
    ],
    "title": "BYTEVALUE Intelligent Flow Control Router Command Injection",
    "updated": "2025-10-15T20:04:48.098000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-78"
    ]
  },
  "nvd": {
    "cpes": [],
    "created": "2025-10-15T02:15:32.177000+00:00",
    "description": "BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is not properly validated and is echoed into a shell context, allowing an attacker to inject and execute arbitrary shell commands on the device. Successful exploitation can lead to writing backdoors, privilege escalation on the host, and full compromise of the router and its management functions. VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {
        "score": 9.3,
        "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
      }
    },
    "nvd_repo_path": "2023/CVE-2023-7311.json",
    "references": [
      "https://blog.csdn.net/zkaqlaoniao/article/details/134328873",
      "https://github.com/adysec/nuclei_poc/blob/49c283b2bbb244c071786a2b768fbdde1b91f38e/poc/web/bytevalue_goform_webread_open_rce.yaml",
      "https://isc.sans.edu/diary/Exploit+against+Unnamed+Bytevalue+router+vulnerability+included+in+Mirai+Bot/30642",
      "https://www.vulncheck.com/advisories/bytevalue-intelligent-flow-control-router-command-injection"
    ],
    "title": null,
    "updated": "2026-06-17T06:52:30.320000+00:00",
    "vendors": [],
    "weaknesses": [
      "CWE-78"
    ]
  },
  "opencve": {
    "changes": [
      {
        "created": "2025-10-15T01:45:00+00:00",
        "data": [
          {
            "details": {
              "new": "BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is not properly validated and is echoed into a shell context, allowing an attacker to inject and execute arbitrary shell commands on the device. Successful exploitation can lead to writing backdoors, privilege escalation on the host, and full compromise of the router and its management functions. VulnCheck has observed this vulnerability being targeted by the Rondo botnet.",
              "old": null
            },
            "type": "description"
          },
          {
            "details": {
              "new": "BYTEVALUE Intelligent Flow Control Router Command Injection",
              "old": null
            },
            "type": "title"
          },
          {
            "details": {
              "added": [
                "CWE-78"
              ],
              "removed": []
            },
            "type": "weaknesses"
          },
          {
            "details": {
              "added": [
                "https://blog.csdn.net/zkaqlaoniao/article/details/134328873",
                "https://github.com/adysec/nuclei_poc/blob/49c283b2bbb244c071786a2b768fbdde1b91f38e/poc/web/bytevalue_goform_webread_open_rce.yaml",
                "https://isc.sans.edu/diary/Exploit+against+Unnamed+Bytevalue+router+vulnerability+included+in+Mirai+Bot/30642",
                "https://www.vulncheck.com/advisories/bytevalue-intelligent-flow-control-router-command-injection"
              ],
              "removed": []
            },
            "type": "references"
          },
          {
            "details": {
              "added": {
                "cvssV4_0": {
                  "score": 9.3,
                  "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "be92c9c5-1c5f-47d5-82c2-cd30f7b82797"
      },
      {
        "created": "2025-10-15T15:00:00+00:00",
        "data": [
          {
            "details": {
              "new": "BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is not properly validated and is echoed into a shell context, allowing an attacker to inject and execute arbitrary shell commands on the device. Successful exploitation can lead to writing backdoors, privilege escalation on the host, and full compromise of the router and its management functions. VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.",
              "old": "BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is not properly validated and is echoed into a shell context, allowing an attacker to inject and execute arbitrary shell commands on the device. Successful exploitation can lead to writing backdoors, privilege escalation on the host, and full compromise of the router and its management functions. VulnCheck has observed this vulnerability being targeted by the Rondo botnet."
            },
            "type": "description"
          }
        ],
        "id": "2c0f9f38-caf7-4162-9482-9c1762db8116"
      },
      {
        "created": "2025-10-15T20:15:00+00:00",
        "data": [
          {
            "details": {
              "added": {
                "ssvc": {
                  "options": {
                    "Automatable": "yes",
                    "Exploitation": "poc",
                    "Technical Impact": "total"
                  },
                  "version": "2.0.3"
                }
              },
              "removed": {},
              "updated": {}
            },
            "type": "metrics"
          }
        ],
        "id": "35893bbc-7c8e-4887-9f0c-6ce4b0774c75"
      },
      {
        "created": "2025-10-21T09:45:00+00:00",
        "data": [
          {
            "details": [
              "bytevalue",
              "bytevalue$PRODUCT$flow_control_router"
            ],
            "type": "first_time"
          },
          {
            "details": {
              "added": [
                "bytevalue",
                "bytevalue$PRODUCT$flow_control_router"
              ],
              "removed": []
            },
            "type": "vendors"
          }
        ],
        "id": "1bf46274-7ca0-45f2-8260-6024c18aa67d"
      }
    ],
    "cpes": {
      "data": [],
      "providers": []
    },
    "created": {
      "data": "2025-10-15T01:19:38.316000+00:00",
      "provider": "mitre"
    },
    "description": {
      "data": "BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is not properly validated and is echoed into a shell context, allowing an attacker to inject and execute arbitrary shell commands on the device. Successful exploitation can lead to writing backdoors, privilege escalation on the host, and full compromise of the router and its management functions. VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.",
      "provider": "mitre"
    },
    "metrics": {
      "cvssV2_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_0": {
        "data": {},
        "provider": null
      },
      "cvssV3_1": {
        "data": {},
        "provider": null
      },
      "cvssV4_0": {
        "data": {
          "score": 9.3,
          "vector": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
        },
        "provider": "mitre"
      },
      "epss": {
        "data": {
          "score": 0.01858
        },
        "provider": "first"
      },
      "kev": {
        "data": {},
        "provider": null
      },
      "ssvc": {
        "data": {
          "options": {
            "Automatable": "yes",
            "Exploitation": "poc",
            "Technical Impact": "total"
          },
          "version": "2.0.3"
        },
        "provider": "vulnrichment"
      },
      "threat_severity": {
        "data": null,
        "provider": null
      }
    },
    "references": {
      "data": [
        "https://blog.csdn.net/zkaqlaoniao/article/details/134328873",
        "https://github.com/adysec/nuclei_poc/blob/49c283b2bbb244c071786a2b768fbdde1b91f38e/poc/web/bytevalue_goform_webread_open_rce.yaml",
        "https://isc.sans.edu/diary/Exploit+against+Unnamed+Bytevalue+router+vulnerability+included+in+Mirai+Bot/30642",
        "https://www.vulncheck.com/advisories/bytevalue-intelligent-flow-control-router-command-injection"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    },
    "title": {
      "data": "BYTEVALUE Intelligent Flow Control Router Command Injection",
      "provider": "mitre"
    },
    "updated": {
      "data": "2026-04-15T00:35:42.020000+00:00",
      "provider": "nvd"
    },
    "vendors": {
      "data": [
        "bytevalue",
        "bytevalue$PRODUCT$flow_control_router"
      ],
      "providers": [
        "enrichment"
      ]
    },
    "weaknesses": {
      "data": [
        "CWE-78"
      ],
      "providers": [
        "mitre",
        "nvd"
      ]
    }
  },
  "vulnrichment": {
    "cpes": [],
    "created": "2025-10-15T01:19:38.316000+00:00",
    "description": "BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is not properly validated and is echoed into a shell context, allowing an attacker to inject and execute arbitrary shell commands on the device. Successful exploitation can lead to writing backdoors, privilege escalation on the host, and full compromise of the router and its management functions. VulnCheck has observed this vulnerability being targeted by the RondoDox botnet campaign.",
    "metrics": {
      "cvssV2_0": {},
      "cvssV3_0": {},
      "cvssV3_1": {},
      "cvssV4_0": {},
      "kev": {},
      "ssvc": {
        "options": {
          "Automatable": "yes",
          "Exploitation": "poc",
          "Technical Impact": "total"
        },
        "version": "2.0.3"
      }
    },
    "references": [],
    "title": "BYTEVALUE Intelligent Flow Control Router Command Injection",
    "updated": "2025-10-15T20:04:44.676000+00:00",
    "vendors": [],
    "vulnrichment_repo_path": "2023/7xxx/CVE-2023-7311.json",
    "weaknesses": []
  }
}
Enrichment data
View JSON API Download JSON