ZeroHour
Story · 1 source · 2 articlesfirst updated ()

0day Rubbish Research Team discloses two CVSS 8.8 command injection flaws: QuantaStor 6.8.3.018 alert-mail smtpPassword injection and persistent OP5 Monitor 9.20 injection despite…

mediumVulnerabilityimportance 45CVE-2025-34115
What's new: First merged summary for this story. Newly disclosed on 2026-09-08: (1) a CVSS 8.8 command injection in QuantaStor 6.8.3.018's alert-mail command via the smtpPassword field, with no CVE cited and no evidence of active exploitation; and (2) confirmation that OP5 Monitor 9.20 remains vulnerable to a CVSS 8.8 command injection even after the CVE-2025-34115 patch, which is opt-in and described as…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

On 2026-09-08, 0day Rubbish Research Team disclosed two command injection (CWE-78) flaws, each scoring CVSS 8.8: one in QuantaStor 6.8.3.018's alert-mail command via the smtpPassword field (no CVE cited, no reported exploitation), and one in OP5 Monitor 9.20…

The 0day Rubbish Research Team published two command injection (CWE-78) disclosures on 2026-09-08, each rated CVSS 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) with network attack vector, low privilege requirement, and high confidentiality, integrity, and availability impact. The first affects QuantaStor 6.8.3.018, where the alert-mail command can be exploited through the smtpPassword field; the disclosure cites no CVE identifier and no evidence of active exploitation. The second affects OP5 Monitor 9.20, where the command injection persists despite the existing CVE-2025-34115 patch; the researchers describe that vendor fix as opt-in and ineffective, meaning administrators who previously applied it may still be exposed.

  • QuantaStor 6.8.3.018: command injection (CWE-78) in the alert-mail command, reachable via the smtpPassword field.
  • OP5 Monitor 9.20: command injection (CWE-78) survives the CVE-2025-34115 patch; the vendor fix is opt-in and deemed ineffective by the researchers.
  • CVE identifiers: CVE-2025-34115 (prior OP5 Monitor fix); no CVE cited for the QuantaStor flaw.
  • Severity: both flaws scored CVSS 8.8 with vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H (network vector, low privileges required, no user interaction, high C/I/A impact).
  • Disclosure: both published publicly on 2026-09-08 by 0day Rubbish Research Team; the QuantaStor issue was disclosed as a 0day without mention of active exploitation.
  • Exposure note (OP5): administrators who previously applied the CVE-2025-34115 fix may still be exposed.

Coverage timeline

  1. · 7d ago
    Full Disclosure· 38
    [0day-rubbish] QuantaStor 6.8.3.018 Command injection in the alert-mail command via the smtpPassword field (8.8)

    QuantaStor 6.8.3.018 has a CVSS 8.8 command injection in its alert-mail command, exploitable via the smtpPassword field.

  2. · 7d ago
    Full Disclosure· 45
    [0day-rubbish] OP5 Monitor 9.20 Command injection surviving the CVE-2025-34115 patch (OPT-IN fix ineffective) (8.8)

    OP5 Monitor 9.20 remains vulnerable to CVSS 8.8 command injection because the CVE-2025-34115 fix is opt-in and ineffective.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-34115
An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint.

An authenticated command injection vulnerability exists in OP5 Monitor through version 7.1.9 via the 'cmd_str' parameter in the command_test.php endpoint. A user with access to the web interface can exploit the 'Test this command' feature to execute arbitrary shell commands as the unprivileged web application user. The vulnerability resides in the configuration section of the application and requires valid login credentials with access to the command testing functionality. This issue is fixed in version 7.2.0.

NVD description · AI analysis pending
8.73%