CVE-2023-54329

Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a malicious payload to trigger the vulnerability and execute commands with system privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:inbit:inbit_messenger:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-01-13 23:15

Updated : 2026-01-30 15:47


NVD link : CVE-2023-54329

Mitre link : CVE-2023-54329

CVE.ORG link : CVE-2023-54329


JSON object : View

Products Affected

inbit

  • inbit_messenger
CWE
CWE-121

Stack-based Buffer Overflow

CWE-787

Out-of-bounds Write