Back

CRITICAL

Unauthenticated Command Injection EG7035-M11 Series

Published Mar 1, 2023

Description

Baicells EG7035-M11 devices with firmware through BCE-ODU-1.0.8 are vulnerable to improper code exploitation via HTTP GET command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods have been tested and validated by a 3rd party analyst and have been confirmed exploitable special thanks to Lionel Musonza for the discovery.

Affected products

Remediation

Vendor solution

Baicells recommends that all customers currently running an earlier version of BCE-ODU-1.0.8 upgrade their product to the BaiCE_BM_2.5.26 firmware.

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Baicells
Published Mar 1, 2023
Updated Mar 7, 2025
Reserved Feb 28, 2023
CISA Vulnrichment
Updated Mar 7, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Baicells
Published Mar 1, 2023
Updated Mar 7, 2025
Exploited since n/a
EUVD-2023-23384