Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w79v-r93f-2r96

Опубликовано: 27 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

An OS command injection

vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted firmware update file via the firmware update route.

An OS command injection

vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted firmware update file via the firmware update route.

EPSS

Процентиль: 53%
0.00291
Низкий

8 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8
nvd
3 месяца назад

An OS command injection vulnerability exists in XWEB Pro version 1.12.1 and prior, enabling an authenticated attacker to achieve remote code execution on the system by supplying a crafted firmware update file via the firmware update route.

EPSS

Процентиль: 53%
0.00291
Низкий

8 High

CVSS3

Дефекты

CWE-78