A critical remote code execution vulnerability exists in Delta Electronics InfraSuite Device Master versions prior to 1.0.5. The Device-status service listens on UDP port 10100 and accepts unverified UDP packets, deserializing their content without proper validation. The flaw is located in the ParseUDPPacket function, which allows unauthenticated attackers to send specially crafted UDP packets that are deserialized, leading to arbitrary code execution as an administrator.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Metasploit module targeting an unauthenticated .NET deserialization vulnerability (CVE-2023-1133) in Delta Electronics InfraSuite Device Master versions below 1.0.5. The exploit leverages the 'ParseUDPPacket()' method in the 'Device-Gateway-Status' process, which insecurely deserializes user-supplied data received over UDP (default port 10100). The module supports both command execution and EXE dropper payloads, allowing remote code execution as the process user. The module includes a check method to fingerprint the target by requesting the web interface's login page and configuration JavaScript to determine product presence and version. The exploit is operational and provides unauthenticated RCE, with endpoints including the UDP service and web interface paths for fingerprinting. The code is written in Ruby and is structured as a standard Metasploit exploit module.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.