Impact
A flaw in SonicCloudOrg sonic‑agent’s Android WebSocket Server within AndroidWSServer.java permits an attacker to supply a crafted 'path' argument that is executed as an operating‑system command. The resulting command injection can lead to arbitrary code execution with the privileges of the running service, thus compromising confidentiality, integrity, and availability of the affected device. The weakness is catalogued as CWE-77 and CWE-78. Because the software versions affected are no longer supported and no vendor patch is available, the vulnerability remains open for exploitation.
Affected Systems
SonicCloudOrg sonic‑agent versions up to and including 2.7.2, all of which are no longer supported by the maintainers. Any deployment that continues to run these versions of the Android WebSocket Server component remains vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of 2% indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers could trigger the injection remotely by sending a WebSocket request with a malicious 'path' parameter; because no vendor patch exists for these unsupported releases, the risk persists until a newer, supported version is adopted.
OpenCVE Enrichment