Impact
The vulnerability allows an attacker to inject system commands through the BGPASPath input field because the input validation uses an unanchored regular expression. This flaw results in remote code execution on the host running the Looking Glass binary, giving the attacker full control over the affected system. The weakness is a classic OS Command Injection problem (CWE-78).
Affected Systems
The affected product is Looking Glass, a stateless network‑diagnostic platform developed by AS203038. The vulnerability exists in any version of Looking Glass prior to 1.3.5; version 1.3.5 and later contain the fix.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. The EPSS score of 1% indicates a very low but non‑zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that attackers can exploit the flaw remotely through the gRPC API, web UI, or CLI, by sending a crafted BGPASPath input to the service. Successful exploitation would give an attacker arbitrary command execution on the host machine.
OpenCVE Enrichment