Home

Description

Due to the improper neutralisation of special elements used in an OS command, an unauthenticated remote attacker can exploit an RCE vulnerability in the com_mb24sysapi module, resulting in full system compromise. This vulnerability is a variant attack for CVE-2020-10383.

PUBLISHED Reserved 2026-03-17 | Published 2026-03-23 | Updated 2026-03-23 | Assigner CERTVDE




CRITICAL: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Problem types

CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

Product status

Default status
unaffected

0.0.0 (semver)
affected

Default status
unaffected

0.0.0 (semver)
affected

Default status
unaffected

0.0.0 (semver)
affected

Default status
unaffected

0.0.0 (semver)
affected

Credits

Moritz Abrell, Christian Zäske from SySS GmbH finder

References

certvde.com/de/advisories/VDE-2026-024

certvde.com/de/advisories/VDE-2026-025

cve.org (CVE-2026-32968)

nvd.nist.gov (CVE-2026-32968)

Download JSON