Description
A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. The device is not correctly checking this configuration value before passing it to an system execute leading to code execution. This can result in a total loss of confidentiality, integrity and availability.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
0.0.0 (semver)
0.0.0 (semver)
8.4.4
3.0.2
0.0.0 (semver)
0.0.0 (semver)
8.4.4
3.0.2
Credits
Moritz Abrell from SySS GmbH
Christian Zäske from SySS GmbH
References
www.certvde.com/en/advisories/VDE-2026-054/