Impact
The vulnerability occurs in the Replication Receiver component of Ahsay CBS, where a malicious value supplied to the 'random' parameter of the /rps/api/json/UpdateReceivers.do endpoint can cause arbitrary OS commands to be executed. This flaw is a classic command injection (CWE‑77/CWE‑78). Successfully exploited, an attacker can gain full control of the server, exfiltrate data, or pivot to other systems, impacting confidentiality, integrity, and availability.
Affected Systems
Affected versions of Ahsay CBS are all releases up to 10.3.2. Versions 10.3.4 and later contain the fix. The software is deployed in enterprise environments managing data replication, and the vulnerability exists in the server‑side code handling replication receiver updates.
Risk and Exploitability
The CVSS score of 10 indicates critical severity. The exploit is publicly available and can be launched remotely via an HTTP request, and it has been reported as published. The EPSS score is not disclosed, but the lack of an available EPSS does not diminish the seriousness of the known exploit. The vulnerability is not listed in CISA’s KEV catalog, yet the documented public exploit and remote launch capability make it an immediate priority for patching.
OpenCVE Enrichment