Impact
An OS command injection flaw in WGDashboard allows an authenticated adversary to run arbitrary shell commands with root privileges. The flaw is triggered by user‑supplied input that is passed directly to the operating system shell, creating a full remote code execution vector. This can lead to complete compromise of the affected system, exposing all data and services and enabling further lateral movement.
Affected Systems
The vulnerability affects the WGDashboard application, specifically all releases 4.2.3 and earlier. Users running these versions are susceptible to exploitation.
Risk and Exploitability
The CVSS score of 9.8 indicates a high severity vulnerability, and the EPSS score of 14% indicates a modest but non‑zero likelihood of exploitation in the wild. Because the attack requires authenticated access to the dashboard, an attacker must first obtain valid credentials or prompt an existing authenticated user to trigger the injection. Once in, the attacker can execute commands as root, causing a catastrophic compromise of confidentiality, integrity, and availability. The vulnerability is not currently listed in CISA’s KEV catalog, but the potential impact warrants vigilance.
OpenCVE Enrichment