[0day-rubbish] Opengear NGCS 25.11.8 Authenticated PDU name command injection to root via io.popen (8.8)
Researchers disclosed an authenticated Opengear NGCS 25.11.8 command-injection bug that executes commands as root.
The 0day Rubbish Research Team publicly disclosed an authenticated command-injection flaw in Opengear NGCS 25.11.8. An administrator can supply a PDU name that is passed to Lua io.popen, resulting in root command execution on the out-of-band console manager. The issue is CWE-78 with CVSS 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The post includes a full technical analysis and a reproducible proof of concept; observed in-the-wild exploitation is not claimed.
- Authenticated administrators can inject OS commands through a PDU name.
- The value reaches Lua io.popen and can run commands as root.
- Scored CVSS 8.8 and tracked as CWE-78 command injection.
- Researchers published analysis and a reproducible proof of concept.
Posted by disclosure via Fulldisclosure on Sep 22 0day Rubbish Research Team is publicly disclosing a vulnerability in Opengear NGCS 25.11.8. Type: Authenticated PDU name command injection to root via io.popen (CWE-78) CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) Impact: root command execution on the out-of-band console manager Authentication: authenticated administrator Full technical analysis and a reproducible proof-of-concept:...
This source does not provide full text. Read it at seclists.org.