Critical severity9.8NVD Advisory· Published Jan 10, 2024· Updated Jun 17, 2026
CVE-2023-31446
CVE-2023-31446
Description
In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- cpe:2.3:o:cassianetworks:xc1000_firmware:2.1.1.2303082218:*:*:*:*:*:*:*
- cpe:2.3:o:cassianetworks:xc2000_firmware:2.1.1.2303090947:*:*:*:*:*:*:*
- Cassia/Cassia Gateway firmwaredescription
- Range: XC1000_2.1.1.2303082218, XC2000_2.1.1.2303090947
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.