Loading HuntDB...

GHSA-89ph-wr9x-hcfc

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup.

Related CVEs

Key Information

GHSA ID
GHSA-89ph-wr9x-hcfc
Published
January 10, 2024 3:30 AM
Last Modified
January 17, 2024 3:30 AM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 30, 2025 6:36 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.