S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jan 8, 2024

CVE-2023-37265 Scanner

Detects 'OS Command Injection' vulnerability in IceWhaleTech CasaOS-Gateway affects v. before 0.4.4.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-37265
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers can execute arbitrary commands as `root` on CasaOS instances. The problem was addressed by improving the detection of client IP addresses in `391dd7f`. This patch is part of CasaOS 0.4.4. Users should upgrade to CasaOS 0.4.4. If they can't, they should temporarily restrict access to CasaOS to untrusted users, for instance by not exposing it publicly.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
CasaOS-Gatewayby IceWhaleTech
< 0.4.4
casaos-gatewayby icewhale
AFFECTED< 0.4.4SAFE ✓≥ 0.4.4
Updated Aug 22, 2026View on NVD →
Detail

The IceWhaleTech CasaOS-Gateway is an open-source Personal Cloud system that provides users with an efficient and secure way to store and manage their data. CasaOS-Gateway is designed to run on various hardware platforms, including single-board computers, and supports a variety of file-sharing protocols, such as SMB, FTP, and NFS. The system provides users with an intuitive web interface that allows them to manage their data and configure their network settings easily.

However, despite the system's potential benefits, it was discovered that CasaOS-Gateway had a critical vulnerability, known as CVE-2023-37265. This vulnerability allowed unauthenticated attackers to execute arbitrary commands as the root user on CasaOS instances. The problem was caused by a lack of IP address verification, which allowed attackers to spoof their IP address and gain unauthorized access to the system.

If exploited, this vulnerability could lead to various consequences, such as data theft and system compromise. Attackers could steal sensitive data, such as login credentials and financial information, or use the compromised system to launch further attacks against other systems.

In conclusion, the IceWhaleTech CasaOS-Gateway is an innovative Personal Cloud system that provides users with an efficient and secure way to store and manage their data. However, a critical vulnerability, known as CVE-2023-37265, was discovered, which could lead to severe consequences if exploited. To protect against this vulnerability, users are advised to take several precautions, as described above. Finally, we encourage all users to check their digital assets for vulnerabilities regularly and quickly learn about vulnerabilities with the pro features of the s4e.io platform.

 

REFERENCES

Solution Advice

To protect against this vulnerability, users are advised to take the following precautions:

  • Upgrade CasaOS-Gateway to version 0.4.4, which includes a patch that improves the detection of client IP addresses.
  • Temporarily restrict access to CasaOS-Gateway to untrusted users, for example, by not exposing it publicly.
  • Install a firewall that blocks incoming traffic from unknown sources or blocks traffic from known malicious IPs.
  • Monitor the CasaOS-Gateway logs and look for signs of suspicious activity.
  • Educate users on how to recognize phishing scams and social engineering attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.