← Back to browse · API

CVE-2023-27394

Severity
CRITICAL
CVSS
9.8
EPSS
0.17571
Risk score
45.35
CISA KEV
No
PoC
No
Published
2023-03-28
Modified
2025-01-16
First seen
2026-08-07
Aliases
EUVD-2023-31170, GHSA-W554-444W-32F7
Products
ProPump and Controls, Inc.:Osprey Pump Controller 1.01
Sources
euvd EUVD-2023-31170

Description

Osprey Pump Controller version 1.01 is vulnerable an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP GET parameter called by DataLogView.php, EventsView.php and AlarmsView.php scripts.

References