CVE-2023-33468: Kramerav Via CONNECT2 Firmware

Critical severity, CVSS 9.1. EPSS: 0.8% chance of exploitation in the next 30 days.

KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly from the physical screen.

Affected products

  • Kramerav Via CONNECT2 Firmware: before 4.0.1.1326 (fixed in 4.0.1.1326)
  • Kramerav Via GO2 Firmware: before 4.0.1.1326 (fixed in 4.0.1.1326)

Published 2023-08-09. Last modified 2026-07-09.