PT-2026-25903 · Perle · Perle Iolan Sts/Scs

·

CVE-2026-23759

·

Publicado

2026-03-17

·

Atualizado

2026-05-01

CVSS v3.1

7.2

Alta

VetorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Perle IOLAN STS/SCS versions prior to 6.0
Description Perle IOLAN STS/SCS terminal server models with firmware versions prior to 6.0 allow authenticated operating system command injection through the restricted shell accessible via Telnet or SSH. The 'ps' command within the shell does not properly sanitize arguments, passing user-supplied parameters to an 'sh -c' invocation that runs with root privileges. An authenticated attacker who can log in to the device can inject shell metacharacters after the 'ps' subcommand to execute arbitrary operating system commands with root privileges, potentially leading to a full compromise of the underlying operating system. The ps command is vulnerable due to improper sanitization of arguments, which are then passed to the sh -c function.
Recommendations Update Perle IOLAN STS/SCS firmware to version 6.0 or later.

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-23759

Produtos afetados

Perle Iolan Sts/Scs