CVE-2023-43744: Zultys Mx-E Firmware
High severity, CVSS 7.2. EPSS: 2% chance of exploitation in the next 30 days.
An OS command injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an administrator to execute arbitrary OS commands via a file name parameter in a patch application function. The Zultys MX Administrator client has a "Patch Manager" section that allows administrators to apply patches to the device. The user supplied filename for the patch file is passed to a shell script without validation. Including bash command substitution characters in a patch file name results in execution of the provided command.
Affected products
- Zultys Mx-E Firmware: before 16.0.4 (fixed in 16.0.4); from 17.0.6, before 17.0.10 (fixed in 17.0.10)
- Zultys Mx-SE Firmware: before 16.0.4 (fixed in 16.0.4); from 17.0.6, before 17.0.10 (fixed in 17.0.10)
- Zultys Mx-SE Ii Firmware: before 16.0.4 (fixed in 16.0.4); from 17.0.6, before 17.0.10 (fixed in 17.0.10)
- Zultys Mx-Virtual Firmware: before 16.0.4 (fixed in 16.0.4); from 17.0.6, before 17.0.10 (fixed in 17.0.10)
- Zultys MX250 Firmware: before 16.0.4 (fixed in 16.0.4); from 17.0.6, before 17.0.10 (fixed in 17.0.10)
- Zultys MX30 Firmware: before 16.0.4 (fixed in 16.0.4); from 17.0.6, before 17.0.10 (fixed in 17.0.10)
Published 2023-12-08. Last modified 2026-06-17.