EXPOSURES › CVE-2023-49897
CVE-2023-49897
HIGH ⌖ ON CISA KEV · EXPLOITEDFXC AE1021/PE devices allow authenticated attackers to execute OS commands via network, enabling remote code execution.
This OS command injection vulnerability in FXC AE1021 and AE1021PE devices allows authenticated users to execute arbitrary commands over the network, creating a critical RCE risk for DIB organizations relying on these network appliances. Because the vulnerability is actively exploited and linked to ransomware campaigns, vendors must prioritize patching and customers should verify firmware versions immediately to prevent unauthorized access and data exfiltration.
Shame score — Active exploitation of a remote code execution vulnerability in widely deployed network appliances indicates a critical security oversight.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
FXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenticated users to execute commands via a network.