Impact
gpsd, up to release 3.27.5, contains a command injection flaw (CWE‑78) in the gpsprof component. The vulnerability is triggered when an attacker controls the GPS device subtype value, which is sourced from a DEVICES JSON log entry or NMEA PGRMT sentence and inserted into a gnuplot "set title" statement. Only double‑quote characters are escaped, so backtick‑enclosed payloads are passed directly to the shell, enabling the execution of arbitrary commands as the gpsprof and gnuplot process. This flaw allows an attacker to compromise confidentiality, integrity, and availability of the host system.
Affected Systems
ntpsec’s gpsd product releases up to and including 3.27.5 are affected. No other vendors or product versions are identified in the CNA data.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity, and the EPSS score of 2% shows a non‑zero likelihood of exploitation. Based on the description, it is inferred that the likely attack vector is local or involves injection of malicious NMEA data into the feed; an attacker must control the GPS device subtype value, which can be achieved by compromising a GPS device or tampering with the NMEA stream received by the system. This is not listed in CISA’s KEV catalog, but the potential for arbitrary shell execution underlines a significant risk that warrants immediate remediation.
OpenCVE Enrichment