← Back

Xc1000 Firmware

xc1000_firmware

Vendor: Cassianetworks • 1 CVE

CVEs (1)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Cassianetworks
2Xc1000 Firmware
Xc2000 Firmware
Jun 20, 2025
Jan 10, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device...Show more
In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup.Show less