CVE-2023-33364: Supremainc Biostar 2

High severity, CVSS 8.8. EPSS: 1.6% chance of exploitation in the next 30 days.

An OS Command injection vulnerability exists in Suprema BioStar 2 before V2.9.1, which allows authenticated users to execute arbitrary OS commands on the BioStar 2 server.

Affected products

  • Supremainc Biostar 2: before 2.9.1 (fixed in 2.9.1)

Published 2023-08-03. Last modified 2026-06-17.