Impact
XING CPTrans‑ME‑X is vulnerable to an operating‑system command injection flaw that allows an attacker to inject arbitrary commands without needing to authenticate. The vulnerability is classified as CWE‑78 and carries a CVSS score of 9.3, indicating a high severity that can compromise system integrity and confidentiality if exploited.
Affected Systems
The affected product is XING CPTrans‑ME‑X from Xing Inc. No specific version information is provided, so all installations of this product should be considered potentially vulnerable until verified.
Risk and Exploitability
Based on the description, it is inferred that the vulnerability can be exploited remotely without authentication. The high CVSS rating, coupled with the fact that the flaw is exploitable remotely and unauthenticated, points to a significant risk of widespread impact if an attacker can reach the target. The EPSS score is 1%, and the CVE is not listed in the CISA KEV catalog, so while the likelihood of exploitation in the wild is uncertain, the potential impact makes the vulnerability a high priority. Attackers could use the injection to execute arbitrary shell commands, potentially leading to full system compromise. The potential for full system compromise is inferred from the nature of OS command injection.
OpenCVE Enrichment