[0day-rubbish] Opengear NGCS 25.11.8 Authenticated PDU name command injection to root via io.popen (8.8)
Researchers disclosed an authenticated Opengear NGCS 25.11.8 command-injection bug that executes commands as root.
The 0day Rubbish Research Team publicly disclosed an authenticated command-injection flaw in Opengear NGCS 25.11.8. An administrator can supply a PDU name that is passed to Lua io.popen, resulting in root command execution on the out-of-band console manager. The issue is CWE-78 with CVSS 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The post includes a full technical analysis and a reproducible proof of concept; observed in-the-wild exploitation is not claimed.
58