Impact
This vulnerability is a classic command injection flaw resulting from improper escaping of a request interface. An unauthenticated remote attacker can send a specially crafted HTTP request that is not correctly sanitized, allowing the attacker to execute arbitrary shell commands as the CSF service account. The impact is the full range of consequences associated with remote code execution, including confidentiality, integrity, and availability damage to the affected system.
Affected Systems
The flaw exists in all versions of the original ConfigServer Security & Firewall software and in WebPros‑maintained forks that contain the unchanged code. WebPros has released a fix in version 16.30; any earlier versions of that fork are vulnerable. Other independent forks or custom builds of CSF may also contain the same vulnerable code and should be examined individually for confirmation.
Risk and Exploitability
The CVSS score of 9.2 signifies a very high severity. Although no EPSS score is available, the ability to run arbitrary commands as the CSF service underscores a high exploitation likelihood. The vulnerability is not listed in CISA’s KEV catalog, but the combination of a remote, unauthenticated vector and privilege escalation presents a critical risk to any host running a vulnerable CSF installation.
OpenCVE Enrichment