PT-2026-50664 · Lms · Lms

·

CVE-2026-40456

·

Published

2026-06-18

·

Updated

2026-06-18

CVSS v4.0

8.6

High

VectorAV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions LMS (LAN Management System) versions prior to commit 9fcb4de
Description An OS Command Injection issue exists where an IP address parameter is passed to the exec() function without proper validation. This allows attackers to execute arbitrary operating system commands on the host.
Recommendations Update to commit 9fcb4de or a newer version. As a temporary workaround, restrict access to the functionality that utilizes the exec() function with IP address parameters.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40456

Affected Products

Lms