CVE-2023-33617Active Exploitation(eparks / fiberlink_210)

MEDIUMCVSS 7.2 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for eparks fiberlink_210 systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An OS Command Injection vulnerability in Parks Fiberlink 210 firmware version V2.1.14_X000 was found via the /boaform/admin/formPing target_addr parameter.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fiberlink_210
  • fiberlink_210_firmware

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
fiberlink_210fiberlink_210_firmware

2 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-01: 1PoC Mentioned / Linked · 2026-07-01: 1Active Exploitation · 2026-07-01: 107-01
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • sicehice@sicehice
    Active Exploitation

    #RCE attempt targeting Parks Fiberlink routers (CVE-2023-33617) 2026-07-01 08:32:07 UTC Source IP: 186.71.90.36 🇪🇨 POST /boaform/adminformLogout//boaform/admin/formPing6 IOCs: hxxp://smart.abuse[.]st/mips smart.abuse[.]st 3a14a2b2123c49565d7741468d3f2565 31.56.209.220 🇦🇪 https://t.co/o1VA455wzW

    Post summary

    The post reports an RCE attempt against Parks Fiberlink routers, providing an IP address and IoC list, which indicates active exploitation activity and the availability of a PoC.

    01102759
    1.7K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
HWeparksfiberlink_210---
OSeparksfiberlink_210_firmware2.1.14_x000--

Explore more