Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vqv4-pwx4-w694

Опубликовано: 15 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.3

Описание

TG8 Firewall contains a pre-authentication remote code execution vulnerability in the runphpcmd.php endpoint. The syscmd POST parameter is passed directly to a system command without validation and executed with root privileges. A remote, unauthenticated attacker can supply crafted values to execute arbitrary operating system commands as root, resulting in full device compromise.

TG8 Firewall contains a pre-authentication remote code execution vulnerability in the runphpcmd.php endpoint. The syscmd POST parameter is passed directly to a system command without validation and executed with root privileges. A remote, unauthenticated attacker can supply crafted values to execute arbitrary operating system commands as root, resulting in full device compromise.

EPSS

Процентиль: 63%
0.00438
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-78

Связанные уязвимости

nvd
3 месяца назад

TG8 Firewall contains a pre-authentication remote code execution vulnerability in the runphpcmd.php endpoint. The syscmd POST parameter is passed directly to a system command without validation and executed with root privileges. A remote, unauthenticated attacker can supply crafted values to execute arbitrary operating system commands as root, resulting in full device compromise.

EPSS

Процентиль: 63%
0.00438
Низкий

9.3 Critical

CVSS4

Дефекты

CWE-78