Beveiligingsadvies

CVE-2025-34035

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-06-24 01:00:23
Laatst bijgewerkt 2026-04-07 14:09:10
Toegewezen door VulnCheck
CVSS-score 10.0
Status PUBLISHED

Beschrijving

An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands. The injected commands are executed with root privileges, leading to full system compromise. Exploitation evidence was observed by the Shadowserver Foundation on 2024-12-05 UTC.