cbcvebase.
CVE-2023-2573
published 2023-05-08

CVE-2023-2573: Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which can be…

PriorityP261high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
4.75%
90.8th percentile
Advantech EKI-1524, EKI-1522, EKI-1521 devices through 1.21 are affected by an command injection vulnerability in the NTP server input field, which can be triggered by authenticated users via a crafted POST request.

Affected

6 ranges
VendorProductVersion rangeFixed in
advantecheki-1521<= 1.21
advantecheki-1521_firmware<= 1.21
advantecheki-1522<= 1.21
advantecheki-1522_firmware<= 1.21
advantecheki-1524<= 1.21
advantecheki-1524_firmware<= 1.21
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.