Impact
An insecure Apache configuration in ConfigServer Security & Firewall maps the /usr/bin directory as CGI programs through the Messenger v3 HTTPS virtual host. A remote, unauthenticated attacker can request one of these mapped executables and execute arbitrary commands as the Apache user, giving full control over the system. This flaw is a classic case of unrestricted command execution as defined by CWE‑552.
Affected Systems
All ConfigServer Security & Firewall installations that have Messenger v3 enabled and are configured to use HTTPS are affected. The issue exists in every version prior to 16.31. The product is distributed by ConfigServer and WebPros.
Risk and Exploitability
The CVSS base score of 9.2 categorizes this vulnerability as critical. EPSS is not available, and it is not in CISA’s KEV catalog, yet the lack of a publicly known exploit does not diminish the potential impact. An attacker can reach the vulnerable configuration from the Internet without any prior authentication, provided that the /usr/bin mapping and Messenger v3 HTTPS virtual host remain active. Successful exploitation grants the attacker Apache‑user execution privileges, enabling complete compromise of the affected system.
OpenCVE Enrichment