Impact
The vulnerability is an OS command injection in the file transfer component of OpenSpug. An attacker can manipulate an unknown function in the /exec/transfer endpoint to execute arbitrary shell commands on the host, leading to full compromise of the system. This flaw corresponds to generic OS command injection weaknesses (CWE-77, CWE-78).
Affected Systems
The issue affects OpenSpug releases up to and including 3.4.0 and 4.0.1, as distributed by OpenSpug:Spug.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. The EPSS score is not available, but the exploit is publicly published and may be in use. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, exploiting the /exec/transfer request over the network. Because the flaw permits unrestricted command execution, any remote attacker who can reach the endpoint can gain full control of the host, making the risk extremely high.
OpenCVE Enrichment