SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2023-49900

CRITICAL · CVSS 9.8 EPSS 0.54% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-16 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

An unauthenticated remote attacker can exploit improperly sanitized user input in the SetParameter command to execute arbitrary code on affected systems. This critical vulnerability poses a significant risk of unauthorized access and control, making it imperative for organizations using the impacted products to prioritize immediate remediation efforts. Security teams should assess their environments for exposure and implement necessary patches or mitigations without delay.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2023-49900
Severity
CRITICAL
CVSS
9.8
EPSS
0.54%

Original NVD Description

An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.