Impact
An OS command injection flaw resides in the openmediavault-md plugin distributed with OpenMediaVault 8.0.4-1. The plugin fails to sanitize user input that is incorporated into shell commands, permitting an attacker to execute arbitrary commands with the privileges of the plugin process. Because the process runs as the system root user, successful exploitation elevates the attacker to full system control, enabling read, write, and delete operations on any local data and the ability to pivot to other network resources.
Affected Systems
OpenMediaVault servers that have the openmediavault-md plugin version 8.0.4-1 installed are affected. This plugin is part of the OpenMediaVault 8.0.4 release series. Systems exposed to untrusted input via the plugin’s web interface or API fall within the vulnerability scope.
Risk and Exploitability
The CVSS score of 9.8 marks the problem as critical. The EPSS score of 1% indicates a low but nonzero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting no confirmed, public exploitation at this time. The attack vector is likely remote, leveraging the plugin’s web interface or REST API. No special conditions beyond having the ability to send requests to the plugin endpoint are stated, so any reachable host that hosts the plugin could potentially be exploited.
OpenCVE Enrichment