CVE-2023-49900: X-Rite Ma-t6

Critical severity, CVSS 9.8. EPSS: 1% chance of exploitation in the next 30 days.

An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.

Affected products

  • X-Rite Ma-t6: before v2.33 (fixed in v2.33)

Published 2026-07-16. Last modified 2026-09-26.