CVE-2023-39854: Atx Ucrypt

Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.

The web interface of ATX Ucrypt through 3.5 allows authenticated users (or attackers using default credentials for the admin, master, or user account) to include files via a URL in the /hydra/view/get_cc_url url parameter. There can be resultant SSRF.

Affected products

  • Atx Ucrypt: up to and including 3.5

Published 2023-10-09. Last modified 2026-06-17.