PT-2026-69114 · Unknown · Nextor Ip Changer

CVE-2026-48098

·

Published

2026-08-07

·

Updated

2026-08-07

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions NexTor IP Changer versions prior to 2.0.0
Description NexTor IP Changer is a command-line tool used to rotate IP addresses via the Tor network. The application executes privileged system commands using sudo and shell=True within its logic. In environments where passwordless sudo (NOPASSWD) is configured, these privileged commands can be executed silently without requiring explicit user confirmation.
Recommendations Update to version 2.0.0.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48098

Affected Products

Nextor Ip Changer