Impact
The vulnerability is an OGNL injection flaw in the login.action endpoint of the Epross AVCON6 systems management platform, allowing unauthenticated attackers to execute arbitrary system commands with root privileges. This is a classic Remote Code Execution (RCE) weakness, categorized as CWE-1334. The impact is full compromise of confidentiality, integrity, and availability of the affected system.
Affected Systems
Affected product: Epross AVCON6 Systems Management Platform. No specific version information is supplied in the CVE record, so all installations of this platform are presumed vulnerable.
Risk and Exploitability
The CVSS score of 9.3 classifies this vulnerability as Critical. The EPSS score of <1% indicates a low current exploitation probability; however, the vulnerability remains exploitable via unauthenticated HTTP requests to the login.action endpoint. It is not listed in the CISA KEV catalog. Attackers can craft payloads in the redirect parameter to instantiate ProcessBuilder objects and run system commands.
OpenCVE Enrichment