SARA / Free Tools / CVE / CVE-2023-40158

CVE-2023-40158 — Hidden functionality vulnerability in the CBC products allows a remote authentic

Hidden functionality vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H, NR8H,

CVSS
EPSS
5.96% (top 9.50%)
CWE
Published
2023-08-23T02:51:29.372Z
Last modified
2024-10-11T21:56:59.562Z
CVSS vector

01What is this vulnerability?

Hidden functionality vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H, NR8H, NR16H series and DR-16F, DR-8F, DR-4F, DR-16H, DR-8H, DR-4H, DR-4M41 series are no longer supported, therefore updates…

02Affected products

VendorProductVersions
CBC Co.,Ltd.NR4H, NR8H, NR16H seriesfirmware all versions
CBC Co.,Ltd.DR16F, DR-8F, DR-4F, DR-16H, DR-8H, DR-4H, DR-4M41 series — firmware all versions
CBC Co.,Ltd.NR4M, NR-8M, NR-16M series — firmware all versions
CBC Co.,Ltd.NR4F, NR-8F, NR-16F series — firmware all versions
CBC Co.,Ltd.DR16M, DR-8M, DR-4M51 series — firmware all versions

03Active exploitation status

Not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog. EPSS is the best forward-looking signal — see the EPSS row above.

04Recommended remediation

05Technical details

For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.

06Detection signatures

Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice:

Open in Sigma generator →

07Related CVEs

No directly-cited follow-up CVEs in the KB record for this advisory. The references list in section 09 carries the vendor cross-references.

08Timeline

09References

Want this in your SOAR or SIEM?
SARA's API returns EPSS, CVSS, KEV, and an analyst-grade summary in one call.
Read the API reference →