CVE-2023-5457: Ailux IMX6

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the “debug” configuration parameter set to “True”) allows a remote unauthenticated attacker to access critical information and have other unspecified impacts to the confidentiality, integrity, and availability of the application. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.

Affected products

  • Ailux IMX6: before 1.0.7-2 (fixed in 1.0.7-2)

Published 2024-03-05. Last modified 2026-06-17.