GHSA-89ph-wr9x-hcfc
GitHub Security Advisory
⚠ Unreviewed
CRITICAL
Has CVE
Advisory Details
In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup.
Related CVEs
Key Information
9.0
/10
Dataset
Last updated: July 30, 2025 6:36 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.