PT-2026-50664 · Lms · Lms
CVSS v4.0
8.6
High
| Vector | AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
LMS (LAN Management System) versions prior to commit 9fcb4de
Description
An OS Command Injection issue exists where an IP address parameter is passed to the
exec() function without proper validation. This allows attackers to execute arbitrary operating system commands on the host.Recommendations
Update to commit 9fcb4de or a newer version.
As a temporary workaround, restrict access to the functionality that utilizes the
exec() function with IP address parameters.Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lms