Home

Description

A command injection vulnerability exists in the eScan Web Management Console version 5.5-2. The application fails to properly sanitize the 'pass' parameter when processing login requests to login.php, allowing an authenticated attacker with a valid username to inject arbitrary commands via a specially crafted password value. Successful exploitation results in remote code execution. Privilege escalation to root is possible by abusing the runasroot utility with mwconf-level privileges.

PUBLISHED Reserved 2025-07-24 | Published 2025-07-25 | Updated 2026-04-07 | Assigner VulnCheck




CRITICAL: 9.4CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Problem types

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-306 Missing Authentication for Critical Function

Product status

Default status
unknown

5.5-2
affected

Credits

Joxean Koret finder

References

www.exploit-db.com/exploits/32869 exploit

raw.githubusercontent.com/...ntivirus/escan_password_exec.rb exploit

www.vulncheck.com/...eb-management-console-command-injection third-party-advisory

cve.org (CVE-2014-125118)

nvd.nist.gov (CVE-2014-125118)

Download JSON