PT-2026-69113 · Unknown · Nextor Ip Changer
CVE-2026-48097
·
Published
2026-08-07
·
Updated
2026-08-07
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
NexTor IP Changer versions prior to 2.0.0
Description
NexTor IP Changer is a command-line tool used to periodically rotate a user's IP address via the Tor network. The software contains a command execution flaw caused by the unsafe use of
shell=True when executing commands that depend on the PATH environment variable for executable resolution. An attacker who can control the execution environment may place a malicious executable, such as sudo, earlier in the PATH to execute arbitrary code.Recommendations
Update to version 2.0.0.
Exploit
Fix
OS Command Injection
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nextor Ip Changer