CVE-2023-22807: Ls-Electric Xbc-DN32U Firmware
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
LS ELECTRIC XBC-DN32U with operating system version 01.80 does not properly control access to the PLC over its internal XGT protocol. An attacker could control and tamper with the PLC by sending the packets to the PLC over its XGT protocol.
Affected products
- Ls-Electric Xbc-DN32U Firmware: version 01.80 only
Published 2023-02-15. Last modified 2026-06-17.