CVE-2026-102256
Beschrijving NL
Onjuiste neutralisatie van speciale elementen die worden gebruikt in een kwetsbaarheid van een besturingssysteemcommando ('OS Command Injection') is geïdentificeerd in het SMA1000-apparaat, waardoor een op afstand geverifieerde aanvaller als beheerder onder specifieke omstandigheden mogelijk willekeurige besturingssysteemcommando's kan uitvoeren, wat resulteert in het uitvoeren van externe code.
Origineel (Engels) tonen
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 appliance which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.