Impact
An OS command injection flaw exists in Seiko Solutions’ SkyBridge MB‑A100 and MB‑A110 devices caused by improper neutralization of special characters in operating‑system commands, and it corresponds to CWE‑78. When exploited, an attacker who can authenticate with administrative privileges can execute arbitrary commands on the device’s underlying OS, potentially compromising device integrity, confidentiality, and availability.
Affected Systems
The vulnerability affects Seiko Solutions Inc.’s SkyBridge MB‑A100 and MB‑A110 devices. All current releases are potentially vulnerable until a vendor patch is applied, as no specific firmware or software version ranges are provided in the CNA data.
Risk and Exploitability
The CVSS score of 8.6 indicates a high severity risk. The EPSS score of 1% reflects a low but non‑negligible likelihood of exploitation, and the issue is not listed in CISA’s KEV catalog. The attack vector is limited to users or systems that can log in as an administrator. Once authenticated, the attacker can inject and run any OS command, leading to full control over the device.
OpenCVE Enrichment