← Πίσω στην αναζήτηση CVE

CVE-2026-49481

UpSnap

Περιγραφή

UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap-s device management functionality due to the presence of unsafe shell command template interpolation using the ip and the mac fields. User-controlled values can be inserted into the wake_cmd and shutdown_cmd templates and executed via /bin/sh -c (Linux) or cmd /C (Windows) without sanitization, resulting in an authenticated Remote Code Execution (RCE). A low-privileged user with permission to create or edit devices can execute arbitrary operating system commands on the UpSnap hosted server. Version 5.4.0 patches the issue.

CVSS 9.6EPSS 0.882%Κίνδυνος 1.04
Προβολή πηγής
Δημοσίευση
2026-08-12 23:17:21
Επηρεαζόμενες εκδόσεις
<5.4.0
Τύπος
Εφαρμογή ιστού
Τελευταία τροποποίηση
2026-08-13 18:17:28
Διάνυσμα
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N