CVE-2023-54329

Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a malicious payload to trigger the vulnerability and execute commands with system privileges.
Configurations

Configuration 1 (hide)

cpe:2.3:a:inbit:inbit_messenger:*:*:*:*:*:*:*:*

History

17 Jun 2026, 06:47

Type Values Removed Values Added
Summary
  • (es) Inbit Messenger 4.6.0 - 4.9.0 contiene una vulnerabilidad de ejecución remota de comandos que permite a atacantes no autenticados ejecutar comandos arbitrarios explotando un desbordamiento de pila en el protocolo del mensajero. Los atacantes pueden enviar paquetes XML especialmente diseñados al puerto 10883 con una carga útil maliciosa para activar la vulnerabilidad y ejecutar comandos con privilegios de sistema.

30 Jan 2026, 15:47

Type Values Removed Values Added
References () https://github.com/a-rey/exploits/blob/main/writeups/Inbit_Messenger/v4.6.0/writeup.md - () https://github.com/a-rey/exploits/blob/main/writeups/Inbit_Messenger/v4.6.0/writeup.md - Exploit, Third Party Advisory
References () https://web.archive.org/web/20200122082432/https://www.softsea.com/review/Inbit-Messenger-Basic-Edition.html - () https://web.archive.org/web/20200122082432/https://www.softsea.com/review/Inbit-Messenger-Basic-Edition.html - Product
References () https://www.exploit-db.com/exploits/51127 - () https://www.exploit-db.com/exploits/51127 - Exploit
References () https://www.vulncheck.com/advisories/inbit-messenger-unauthenticated-remote-command-execution-rce - () https://www.vulncheck.com/advisories/inbit-messenger-unauthenticated-remote-command-execution-rce - Third Party Advisory
First Time Inbit
Inbit inbit Messenger
CPE cpe:2.3:a:inbit:inbit_messenger:*:*:*:*:*:*:*:*
CWE CWE-787

14 Jan 2026, 20:16

Type Values Removed Values Added
References () https://github.com/a-rey/exploits/blob/main/writeups/Inbit_Messenger/v4.6.0/writeup.md - () https://github.com/a-rey/exploits/blob/main/writeups/Inbit_Messenger/v4.6.0/writeup.md -

13 Jan 2026, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-13 23:15

Updated : 2026-06-17 06:47


NVD link : CVE-2023-54329

Mitre link : CVE-2023-54329

CVE.ORG link : CVE-2023-54329


JSON object : View

Products Affected

inbit

  • inbit_messenger
CWE
CWE-121

Stack-based Buffer Overflow

CWE-787

Out-of-bounds Write