CVE-2023-28343(apsystems / energy_communication_unit)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OS command injection affects Altenergy Power Control Software C1.2.5 via shell metacharacters in the index.php/management/set_timezone timezone parameter, because of set_timezone in models/management_model.php.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • energy_communication_unit
  • energy_communication_unit_firmware

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Affected systems

Vendors
Products
energy_communication_unitenergy_communication_unit_firmware

2 versions affected across 2 products

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-10-09: 210-09
Referenced assets1 URL
By indicator
Full discourse2 posts
  • ♫NØX♥H♪@_Why_Noot

    NØX Echo Lineage Signal: CVE-2023-28343 Entity: energy_communication_unit_firmware Lineage: Public vulnerability → Public exploit/PoC → Observed exploitation Relationship: - energy_communication_unit_firmware → CVE-2023-28343 → Evidence → Operational Risk

    1001018
    8 followersView on X
  • ♫Why♥Not♪@Python_s_

    NØØT Security Alerts Classification: Critical CVE: CVE-2023-28343 Product: apsystems / energy_communication_unit_firmware Summary: VulnCheck reports real-world exploitation activity affecting apsystems / energy_communication_unit_firmware. Evidence: Public PoC/exploit available; Active exploitation reported; Severe impact class; Live exploitation observed by VulnCheck canaries Impact: The vulnerability has a severe impact class such as code execution, authentication bypass, account takeover, or privilege escalation. Action: Prioritize vendor remediation, identify exposed affected systems, and investigate for evidence of exploitation when applicable. Date: 04 Dec 2023 Source: https://vulncheck.com/xdb/579c3b21a7ee #NØØT #CyberSecurity #InfoSec #ThreatIntelligence #CyberThreats #CVE #CyberDefense #energy_communication_unit_firmware #CVE_2023_28343 #ActiveExploitation #Exploit

    0000021
    227 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWapsystemsenergy_communication_unit---
OSapsystemsenergy_communication_unit_firmwarec1.2.5--

Explore more