Impact
An OS command injection flaw in the Blue Angel Software Suite’s webctrl.cgi script allows an authenticated attacker to supply malicious input via the ping_addr parameter in a GET request. The application forwards that input directly to the system ping command without sanitization, enabling the attacker to append shell metacharacters and execute arbitrary commands. Because the script runs with root privileges on the embedded Linux device, the injected commands execute as root, and the command output is returned to the web interface, giving the attacker immediate feedback. This vulnerability provides full remote code execution for any user who can authenticate to the web console, including those who use the factory default or backdoor credentials.
Affected Systems
5VTechnologies Blue Angel Software Suite running on embedded Linux devices. No specific version information was disclosed; any installation that includes the webctrl.cgi script and the pingtest_update functionality is potentially affected.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity, and the EPSS of 2% shows that exploitation is considered moderately likely in the near term. The vulnerability is not yet listed in the CISA KEV catalog. Attackers can exploit the flaw remotely via the web interface if they can authenticate, which can be trivially achieved with default or backdoor credentials that many devices ship with. Successful exploitation results in arbitrary root command execution, allowing full control over the device and any networked resources it manages.
OpenCVE Enrichment
EUVD