CVE-2023-48257
HIGHDescription
The vulnerability allows a remote attacker to access sensitive data inside exported packages or obtain up to Remote Code Execution (RCE) with root privileges on the device. The vulnerability can be exploited directly by authenticated users, via crafted HTTP requests, or indirectly by unauthenticated users, by accessing already-exported backup packages, or crafting an import package and inducing an authenticated victim into sending the HTTP upload request.
Is your site exposed to CVE-2023-48257?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| bosch | nexo-os |
| bosch | nexo_cordless_nutrunner_nxa011s-36v-b_\(0608842012\) |
| bosch | nexo_cordless_nutrunner_nxa011s-36v_\(0608842011\) |
| bosch | nexo_cordless_nutrunner_nxa015s-36v-b_\(0608842006\) |
| bosch | nexo_cordless_nutrunner_nxa015s-36v_\(0608842001\) |
| bosch | nexo_cordless_nutrunner_nxa030s-36v-b_\(0608842007\) |
| bosch | nexo_cordless_nutrunner_nxa030s-36v_\(0608842002\) |
| bosch | nexo_cordless_nutrunner_nxa050s-36v-b_\(0608842008\) |
| bosch | nexo_cordless_nutrunner_nxa050s-36v_\(0608842003\) |
| bosch | nexo_cordless_nutrunner_nxa065s-36v-b_\(0608842014\) |
| bosch | nexo_cordless_nutrunner_nxa065s-36v_\(0608842013\) |
| bosch | nexo_cordless_nutrunner_nxp012qd-36v-b_\(0608842010\) |
| bosch | nexo_cordless_nutrunner_nxp012qd-36v_\(0608842005\) |
| bosch | nexo_cordless_nutrunner_nxv012t-36v-b_\(0608842016\) |
| bosch | nexo_cordless_nutrunner_nxv012t-36v_\(0608842015\) |
| bosch | nexo_special_cordless_nutrunner_\(0608pe2272\) |
| bosch | nexo_special_cordless_nutrunner_\(0608pe2301\) |
| bosch | nexo_special_cordless_nutrunner_\(0608pe2514\) |
| bosch | nexo_special_cordless_nutrunner_\(0608pe2515\) |
| bosch | nexo_special_cordless_nutrunner_\(0608pe2666\) |
| bosch | nexo_special_cordless_nutrunner_\(0608pe2673\) |
References
Frequently Asked Questions
What is CVE-2023-48257? +
How severe is CVE-2023-48257? +
What products are affected by CVE-2023-48257? +
How do I check if I'm vulnerable to CVE-2023-48257? +
Related Vulnerabilities
ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's passwords solely from the user’s date of birth (e.g., 12072000 …
The firmware for the EVbee DC-80 has a weak hardcoded root password, which allows attackers to login as root using …
Under certain circumstances the Software House C●CURE 9000 installer will utilize weak credentials.
Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it. …
Tokens in CTFd used for account activation and password resetting can be used interchangeably for these operations. When used, they …
Open Access Management (OpenAM) is an access management solution. Prior to 16.1.1, the OAuth2 authentication module updates an existing local …