Description
An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMessageCodec.java component
Published: 2026-05-28
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that an attacker does not need authentication to trigger arbitrary code execution by sending crafted data to the Cmpp7FDeliverRequestMessageCodec component within SMSGate sms-core. The flaw is a deserialization vulnerability that allows execution of malicious byte streams, giving the attacker full control over the affected host. The weakness is a classic instance of deserializing untrusted data, a high‑severity class of bugs that compromise confidentiality, integrity, and availability of the system.

Affected Systems

The vulnerability exists in SMSGate sms-core versions 2.1.13.6 and earlier. No vendor name is provided, but any deployment of the affected sms-core library is susceptible.

Risk and Exploitability

The vulnerability is remotely exploitable and requires the ability to inject data into the vulnerable component. No EPSS score is published and the issue is not listed in CISA’s KEV catalog, yet the potential for full system compromise makes it highly dangerous. Post‑exploit privileges would depend on the service account under which the component runs, but given the unrestricted nature of the code execution path, privilege escalation is a clear risk.

Generated by OpenCVE AI on May 28, 2026 at 15:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update SMSGate sms-core to a version newer than 2.1.13.6 or apply the vendor’s security patch.
  • If an update cannot be applied immediately, isolate the affected service from external networks and limit its exposure to trusted hosts only.
  • Implement strict security controls such as network segmentation, intrusion detection monitoring, and regular audit of the component’s input streams to detect anomalous traffic.

Generated by OpenCVE AI on May 28, 2026 at 15:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 28 May 2026 16:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Unvalidated Deserialization in SMSGate sms-core
Weaknesses CWE-502

Thu, 28 May 2026 14:15:00 +0000

Type Values Removed Values Added
Description An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMessageCodec.java component
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-28T13:25:49.577Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-37579

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-05-28T14:16:19.427

Modified: 2026-05-28T14:16:19.427

Link: CVE-2026-37579

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-28T16:00:14Z

Weaknesses