PT-2025-51946 · Hisecos · Hisecos

·

CVE-2023-53908

·

Published

2025-12-17

·

Updated

2025-12-20

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions HiSecOS version 04.0.01
Description The software contains a flaw that allows authenticated users to change their access level. This is possible through specially crafted XML payloads sent to the /mops data API endpoint using NETCONF configuration. By manipulating the role value within the XML, attackers can elevate their privileges to an administrative level.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the /mops data API endpoint to minimize the risk of exploitation.

Exploit

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-53908

Affected Products

Hisecos