Impact
Electerm's calculate size feature builds an unescaped shell command from the folder name, allowing a malicious FTP or SFTP host to execute arbitrary shell commands on the client when a user selects an attacker‑controlled folder. This is a classic command injection flaw (CWE‑78) that can lead to local code execution with the privileges of the user running the application.
Affected Systems
The bug exists in all Electerm releases earlier than 3.15.120. Users must verify that their installed version is at least 3.15.120.
Risk and Exploitability
The CVSS score of 8.8 classifies it as high severity. EPSS indicates a very low probability of exploitation, and the issue is not present in CISA's KEV catalog. Nevertheless, the flaw can be triggered only when a user explicitly opens properties on a folder supplied by a malicious server, so the attack vector is local via the client interface. Adequate patching or avoidance of the vulnerable operation mitigates the risk.
OpenCVE Enrichment