CVE-2023-7311 is an OS command injection vulnerability in the BYTEVALUE Intelligent Flow Control Router's webRead open endpoint. The endpoint improperly validates the path parameter and echoes its value into a shell context, allowing a remote, unauthenticated attacker to execute arbitrary shell commands without user interaction. Exploitation can enable backdoor installation, host privilege escalation, and full compromise of the router and its management functions. The RondoDox botnet campaign has targeted this vulnerability. Specific affected releases and a fixed version are not identified.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical command injection vulnerability in BYTEVALUE Intelligent Flow Control Router allows unauthenticated remote attackers to execute arbitrary shell commands through the improperly validated path parameter at /goform/webRead/open. Exploitation can enable backdoor installation, privilege escalation, and complete compromise of the router and its management functions. The record assigns a CVSS v4.0 score of 9.3 and identifies the vulnerability as known exploited.
A vulnerability in BYTEVALUE routers, exploited by the frost malware.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.