Description
meterN 1.2.3 contains an authenticated remote code execution vulnerability in admin_meter2.php and admin_indicator2.php scripts. Attackers can exploit the 'COMMANDx' and 'LIVECOMMANDx' POST parameters to execute arbitrary system commands with administrative privileges.
Problem types
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
Credits
LiquidWorm as Gjoko Krstic of Zero Science Lab
References
www.exploit-db.com/exploits/50596 (ExploitDB-50596)
web.archive.org/web/20210617084455/https://www.metern.org/ (Archived Vendor Homepage)
www.zeroscience.mk/en/vulnerabilities/ZSL-2021-5690.php (Zero Science Lab Disclosure (ZSL-2021-5690))
www.vulncheck.com/...remote-code-execution-via-admin-scripts (VulnCheck Advisory: meterN 1.2.3 Authenticated Remote Code Execution via Admin Scripts)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.