LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-49897: FXC AE1021, AE1021PE OS Command Injection Vulnerability

RBRecent Breaches Vulnerability Intelligence·Dec 21, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Jan 11, 2024
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-49897 to its Known Exploited Vulnerabilities catalog on Dec 21, 2023, with a federal patch deadline of Jan 11, 2024 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

FXC AE1021 and AE1021PE contain an OS command injection vulnerability that allows authenticated users to execute commands via a network.

CVE-2023-49897 is an OS command injection vulnerability affecting FXC AE1021 and AE1021PE products. Per the CISA summary, it allows authenticated users to execute operating system commands via a network. This class of flaw can let an attacker with valid credentials run arbitrary commands on the device, risking full compromise of the system and any connected resources.

Defenders should treat it seriously because network-accessible command execution on infrastructure devices often expands an attacker's foothold. Specifics such as exact firmware versions or attack vectors must be confirmed against the vendor advisory; public detail beyond the CWE-78 classification and authentication requirement is limited.

How it works

The vulnerability is classified as CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'). In products of this type, user-supplied input that reaches a shell or system command interpreter is not properly sanitized. An authenticated attacker who can reach the vulnerable network interface can craft input that injects additional commands, causing the device to execute them with the privileges of the underlying process.

Because the CISA summary states the issue is reachable via a network by authenticated users, the attacker first needs valid credentials or an existing session. Once authenticated, the injection allows command execution without needing further local access. No further exploit mechanics, payloads, or prerequisites are provided in the available facts, so teams should not assume unauthenticated access or specific interfaces; always validate against the vendor advisory.

Am I affected? How to find it in your systems

FXC AE1021 and AE1021PE devices are the only products named. Inventory any network-attached hardware or appliances matching these model numbers. Typical locations include edge or branch network equipment, management interfaces, or dedicated appliance deployments. Use asset management tools, network discovery scans, or configuration management databases to locate them by model string, MAC OUI if known, or management web/SSH banners.

Absence of public exploit details means telemetry will be general for command-injection attempts rather than signature-based for this CVE alone.

How to remediate

The CISA required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Prioritize obtaining and installing the vendor-supplied update or configuration change that addresses CVE-2023-49897. Confirm the exact fixed release and installation procedure directly from the vendor advisory before deployment.

If you can't patch immediately

Until the vendor mitigation can be applied, reduce exposure with compensating controls. Isolate the devices on dedicated management VLANs or network segments that only authorized administrators can reach. Restrict source IP addresses that may authenticate to the management plane.

Document the compensating controls and set a firm timeline for applying the permanent vendor fix.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to device compromise and subsequent data exposure or lateral movement. Known ransomware use is not documented for this CVE. If you suspect exploitation, preserve logs, isolate affected systems, and follow your incident response process. As a quick check for previously leaked credentials, you can run a free exposure scan of your email addresses against known breach data sets.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedFXC · AE1021, AE1021PE
WeaknessCWE-78
Added to CISA KEVDec 21, 2023
Federal patch deadlineJan 11, 2024
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities