Impact
An OS command injection flaw in WGDashboard allows an authenticated adversary to run arbitrary shell commands with root privileges. The flaw is triggered by user-supplied input that is passed directly to the operating system shell, creating a full remote code execution vector. This can lead to complete compromise of the affected system, exposing all data and services and enabling further lateral movement.
Affected Systems
The vulnerability affects the WGDashboard application, specifically all releases 4.2.3 and earlier. Users running these versions are susceptible to exploitation.
Risk and Exploitability
The CVSS score is not publicly listed, and EPSS data is unavailable, indicating that the vulnerability is recognized but the exact likelihood of exploitation in the wild is unknown. Because the attack requires authenticated access to the dashboard, an attacker must first obtain valid credentials or prompt an existing authenticated user to trigger the injection. Once in, the attacker can execute commands as root, causing a catastrophic compromise of confidentiality, integrity, and availability. The vulnerability is not currently listed in CISA’s KEV catalog, but the potential impact warrants vigilance.
OpenCVE Enrichment