Back to Labs
Security Advisory

CVE-2023-24078

About

Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/.

Weakness (CWE):CWE-94

Rainforest analyst review

Real Time Logic FuguHub 8.1 and earlier contains a remote code execution flaw reachable through the /FuguHub/cmsdocs/ component. The metrics indicate a low-privileged account is the precondition, so this is an authenticated user turning access to that component into code execution on the host, network-reachable and requiring no user interaction once that low privilege is in hand.

FuguHub is a niche embedded application/server platform, not a mass-market target, so it won't draw the same indiscriminate scanning as a popular CMS, and the low-privilege requirement narrows the attacker pool further to those who can obtain an account. That said, RCE on an embedded server is a strong outcome for whoever does clear the bar, and embedded devices often lack the monitoring that would catch it.

Given the specialized footprint, our first job is discovery, do we run FuguHub anywhere, at 8.1 or earlier, and is its interface exposed. Because it is a specific URL path, /FuguHub/cmsdocs/, it lends itself to a virtual-patch rule and log hunting while updates are arranged, and we would confirm that low-privilege accounts on the platform are tightly controlled since that account is the entry ticket.

References

Related CVEs

Frequently asked questions

What is CVE-2023-24078?

Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/.

How severe is CVE-2023-24078?

CVE-2023-24078 carries a CVSS 3.1 base score of 8.8, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 89 out of 100, in the critical band.

How is CVE-2023-24078 exploited?

According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required Low, user interaction None. Impact on confidentiality High, integrity High and availability High.

Which products are affected by CVE-2023-24078?

Public advisories list the following as affected: fuguhub. Check the references on this page for the exact versions each vendor confirms.

How do I fix CVE-2023-24078?

Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.

Empower Your Security Strategy with Rainforest

Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.

Share this:LinkedInX Email