Impact
An OS command injection flaw exists in the wake_cmd and shutdown_cmd templates of the UpSnap web application. User-held values of the ip and mac fields are inserted unsafely into shell command templates, allowing execution of arbitrary operating system commands via /bin/sh -c on Linux or cmd /C on Windows. The flaw is authenticated; a low‑privileged user with permission to create or edit device entries can trigger the injection, resulting in full control over the host running UpSnap. The vulnerability is classified as CWE‑78.
Affected Systems
UpSnap, a wake‑on‑LAN web application from seriousm4x, is affected in all releases prior to version 5.4.0. No specific patch versions are listed beyond the 5.4.0 release that addresses the issue.
Risk and Exploitability
The vulnerability carries a CVSS base score of 9.6, indicating critical severity. Exploitation requires authenticated access with device‑management rights, enabling the attacker to craft device records containing malicious shell commands. An attacker may propagate the flaw once the user logs in or can perform it remotely if they are already authenticated. The EPSS score is not presently available, and the flaw is not listed in the CISA KEV catalog, but its high CVSS score and ease of exploitation via trusted credentials make it a significant risk.
OpenCVE Enrichment