CVE-2023-7305

High PUBLISHED

SmartBI RMIServlet Unrestricted File Upload RCE

Guangzhou Smart Software Co., Ltd. · SmartBI

Not yet in CISA KEV

Exploited in the wild

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
9.2 Critical EPSS 0.5%

At a Glance

SmartBI V8, V9, and V10 contain an unrestricted file upload vulnerability via the RMIServlet request handling logic. Under certain configurations or usage patterns, attackers can send specially crafted requests that cause the application to perform sensitive operations or execute arbitrary code on the host. The vendor released a fix in July 2023 to address the underlying flaw. VulnCheck has observed this vulnerability being exploited in the wild.

CVE Published
Oct 15, 2025
Exploitation Reported
Jun 01, 2026
CVSS
9.2 Critical
EPSS
0.5%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
Guangzhou Smart Software Co., Ltd.
SmartBI

V8 to < July 2023 update

Affected
Guangzhou Smart Software Co., Ltd.
SmartBI

V9 to < July 2023 update

Affected
Guangzhou Smart Software Co., Ltd.
SmartBI

V10 to < July 2023 update

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.