Impact
An OS command injection flaw exists in the API endpoint of Datiphy Data Management Center from version 8.3.0 through 8.5.1. The vulnerability is enabled only for authenticated administrators, allowing them to execute arbitrary operating‑system commands with root privileges. This flaw is an example of CWE‑78 (OS Command Injection) and can be used to gain complete control over the host machine, leading to full data theft, tampering, or service disruption.
Affected Systems
The affected product is Datiphy Inc.’s Data Management Center, specifically the versions listed in the vulnerability, from 8.3.0 up to and including 8.5.1. Users running any of these releases are at risk.
Risk and Exploitability
The CVSS score of 9.4 indicates critical severity. Although EPSS data is not available, the absence of a KEV listing does not reduce the risk; the vulnerability requires administrative rights, which are typically controlled but still present in many deployments. Attackers who gain or possess administrator credentials can remotely trigger the injection and execute commands as root, making this a high‑impact, highly exploit‑worthy vulnerability.
OpenCVE Enrichment