Description
A vulnerability has been found in SonicCloudOrg sonic-agent up to 2.7.2. The affected element is an unknown function of the file AndroidWSServer.java of the component Android WebSocket Server. The manipulation of the argument path leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
Published: 2026-07-12
Score: 5.3 Medium
EPSS: 1.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in SonicCloudOrg sonic‑agent’s Android WebSocket Server within AndroidWSServer.java permits an attacker to supply a crafted 'path' argument that is executed as an operating‑system command. The resulting command injection can lead to arbitrary code execution with the privileges of the running service, thus compromising confidentiality, integrity, and availability of the affected device. The weakness is catalogued as CWE-77 and CWE-78. Because the software versions affected are no longer supported and no vendor patch is available, the vulnerability remains open for exploitation.

Affected Systems

SonicCloudOrg sonic‑agent versions up to and including 2.7.2, all of which are no longer supported by the maintainers. Any deployment that continues to run these versions of the Android WebSocket Server component remains vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of 2% indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers could trigger the injection remotely by sending a WebSocket request with a malicious 'path' parameter; because no vendor patch exists for these unsupported releases, the risk persists until a newer, supported version is adopted.

Generated by OpenCVE AI on August 1, 2026 at 11:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Disable the Android WebSocket Server component to eliminate the vulnerable code path.
  • Restrict inbound traffic to the WebSocket endpoint by configuring firewalls or ACLs to allow only trusted hosts.
  • Monitor the system for any attempts to connect to the WebSocket endpoint and review logs for suspicious activity.
  • Check the vendor’s website regularly for any patches or newer supported versions, and apply them as soon as available.

Generated by OpenCVE AI on August 1, 2026 at 11:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 12 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in SonicCloudOrg sonic-agent up to 2.7.2. The affected element is an unknown function of the file AndroidWSServer.java of the component Android WebSocket Server. The manipulation of the argument path leads to os command injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
Title SonicCloudOrg sonic-agent Android WebSocket Server AndroidWSServer.java os command injection
First Time appeared Soniccloudorg
Soniccloudorg sonic-agent
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:soniccloudorg:sonic-agent:*:*:*:*:*:*:*:*
Vendors & Products Soniccloudorg
Soniccloudorg sonic-agent
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Soniccloudorg Sonic-agent
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-15T16:13:17.023Z

Reserved: 2026-07-11T12:23:54.881Z

Link: CVE-2026-15495

cve-icon Vulnrichment

Updated: 2026-07-15T16:12:42.767Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T11:15:03Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')