ZeroHour

CVE-2023-27886

CVSS 3.1
9.8 critical
EPSS
2%p74
Published
()
Modified
Description

Osprey Pump Controller version 1.01 is vulnerable to an unauthenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through a HTTP POST parameter called by index.php script.

Vendors
propumpservice
Products
osprey pump controller firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.