CVE-2023-53945: Brainycp

High severity, CVSS 8.8. EPSS: 1.1% chance of exploitation in the next 30 days.

BrainyCP 1.0 contains an authenticated remote code execution vulnerability that allows logged-in users to inject arbitrary commands through the crontab configuration interface. Attackers can exploit the crontab endpoint by adding a malicious command that spawns a reverse shell to a specified IP and port.

Affected products

Published 2025-12-19. Last modified 2026-06-17.