Impact
OS command injection in the advanced-rule parser of ConfigServer Security & Firewall allows a remote attacker who can control a configured allow/deny feed to execute arbitrary commands with root privileges, jeopardizing both confidentiality and integrity of the infected system. This injection flaw (CWE-78) occurs because the parser does not properly validate rule data supplied by the feed, enabling the execution of unintended system commands. The attacker could install malware, exfiltrate data, or pivot to other systems within the network.
Affected Systems
Products affected include ConfigServer Security & Firewall as originally distributed by ConfigServer, as well as the WebPros-maintained fork that contains the same vulnerable code. WebPros has released version 16.30 that addresses the issue; earlier versions of either product, plus any other forks or independently maintained versions that include the vulnerable code, may still be vulnerable and should be reviewed. Administrators should verify the version of CSF installed on each host and apply the patch or upgrade accordingly.
Risk and Exploitability
The CVSS base score of 9.5 indicates critical severity. Although EPSS data is not available, the lack of a KEV listing suggests no widespread exploitation has yet been observed, but the vulnerability remains highly actionable given the root-level impact. The primary attack vector is likely via the attacker’s ability to supply or modify the allow/deny feed, which may be possible if they compromise the administrative interface or physically access the host. In environments where the feed is sourced from an untrusted or compromised origin, the risk is elevated. Prompt patching is essential to eliminate the attack surface.
OpenCVE Enrichment