A flaw in the input validation in TOBY-L2 allows a user to execute arbitrary operating system commands using specifically crafted AT commands. This vulnerability requires physical access to the serial interface of the module or the ability to modify the system or software which uses its serial interface to send malicious AT commands. Exploitation of the vulnerability gives full administrative (root) privileges to the attacker to execute any operating system command on TOBY-L2 which can lead to modification of the behavior of the module itself as well as the components connected with it (depending on its rights on other connected systems). It can further provide the ability to read system level files and hamper the availability of the module as well.. This issue affects TOBY-L2 series: TOBY-L200, TOBY-L201, TOBY-L210, TOBY-L220, TOBY-L280.
Conclusion & alert: CVE-2023-0011 is rated Moderate Risk (44/100): CVSS High severity, with low exploitation likelihood (EPSS 0.48%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.06% | 0.48% | +0.43% |
| 2 | 2025-03-19 | 0.04% | 0.06% | +0.01% |
| 3 | 2025-03-17 | — | 0.04% | — |
Full EPSS history (5 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.6 | 3.1 | HIGH |
|
0.9 | 6.0 | [email protected] |
| 6.8 | 3.1 | MEDIUM |
|
0.9 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| u-blox | toby-l200_firmware | — | cpe:2.3:o:u-blox:toby-l200_firmware:-:*:*:*:*:*:*:* |
| u-blox | toby-l201_firmware | — | cpe:2.3:o:u-blox:toby-l201_firmware:-:*:*:*:*:*:*:* |
| u-blox | toby-l210_firmware | — | cpe:2.3:o:u-blox:toby-l210_firmware:-:*:*:*:*:*:*:* |
| u-blox | toby-l220_firmware | — | cpe:2.3:o:u-blox:toby-l220_firmware:-:*:*:*:*:*:*:* |
| u-blox | toby-l280_firmware | — | cpe:2.3:o:u-blox:toby-l280_firmware:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.u-blox.com/en/report-security-issues | Vendor Advisory |