OS command injection vulnerability in the CBC products allows a remote authenticated attacker to execute an arbitrary OS command on the device or alter its settings. As for the affected products/versions, see the detailed information provided by the vendor. Note that NR4H, NR8H, NR16H series and DR-16F, DR-8F, DR-4F, DR-16H, DR-8H, DR-4H, DR-4M41 series are no longer supported, therefore updates for those products are not provided.
Conclusion & alert: CVE-2023-40144 is rated High Risk (67.1/100): CVSS High severity, with high exploitation likelihood (EPSS 8.09%, 92th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-18 | 8.52% | 8.09% | -0.43% |
| 2 | 2026-04-03 | 10.12% | 8.52% | -1.61% |
| 3 | 2026-03-16 | — | 10.12% | — |
Full EPSS history (16 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| cbc | nr4h_firmware | — | cpe:2.3:o:cbc:nr4h_firmware:-:*:*:*:*:*:*:* |
| cbc | nr8h_firmware | — | cpe:2.3:o:cbc:nr8h_firmware:-:*:*:*:*:*:*:* |
| cbc | nr16h_firmware | — | cpe:2.3:o:cbc:nr16h_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-16f42a_firmware | — | cpe:2.3:o:cbc:dr-16f42a_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-16f45at_firmware | — | cpe:2.3:o:cbc:dr-16f45at_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-8f42a_firmware | — | cpe:2.3:o:cbc:dr-8f42a_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-8f45at_firmware | — | cpe:2.3:o:cbc:dr-8f45at_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-4fx1_firmware | — | cpe:2.3:o:cbc:dr-4fx1_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-16h_firmware | — | cpe:2.3:o:cbc:dr-16h_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-8h_firmware | — | cpe:2.3:o:cbc:dr-8h_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-4h_firmware | — | cpe:2.3:o:cbc:dr-4h_firmware:-:*:*:*:*:*:*:* |
| cbc | drh8-4m41-a_firmware | — | cpe:2.3:o:cbc:drh8-4m41-a_firmware:-:*:*:*:*:*:*:* |
| cbc | nr8-4m71_firmware | — | cpe:2.3:o:cbc:nr8-4m71_firmware:-:*:*:*:*:*:*:* |
| cbc | nr8-8m72_firmware | — | cpe:2.3:o:cbc:nr8-8m72_firmware:-:*:*:*:*:*:*:* |
| cbc | nr-16m_firmware | — | cpe:2.3:o:cbc:nr-16m_firmware:-:*:*:*:*:*:*:* |
| cbc | nr-16f85-8pra_firmware | — | cpe:2.3:o:cbc:nr-16f85-8pra_firmware:-:*:*:*:*:*:*:* |
| cbc | nr-16f82-16p_firmware | — | cpe:2.3:o:cbc:nr-16f82-16p_firmware:-:*:*:*:*:*:*:* |
| cbc | nr-4f_firmware | — | cpe:2.3:o:cbc:nr-4f_firmware:-:*:*:*:*:*:*:* |
| cbc | nr-8f_firmware | — | cpe:2.3:o:cbc:nr-8f_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-16m52_firmware | — | cpe:2.3:o:cbc:dr-16m52_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-16m52-av_firmware | — | cpe:2.3:o:cbc:dr-16m52-av_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-8m52-av_firmware | — | cpe:2.3:o:cbc:dr-8m52-av_firmware:-:*:*:*:*:*:*:* |
| cbc | dr-4m51-av_firmware | — | cpe:2.3:o:cbc:dr-4m51-av_firmware:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://download.ganzsecurity.pl/ | Product |
| https://ganzsecurity.com/release/1578/digimasterpixelmaster-security-notice | Vendor Advisory |
| https://jvn.jp/en/vu/JVNVU92545432/ | Third Party Advisory |