Impact
The vulnerability exists in the shellExecCommand function of chenhg5 cc-connect's Management API. An attacker can manipulate the exec argument to inject operating‑system commands. Successful exploitation allows remote execution of arbitrary commands, compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
This flaw affects all installations of chenhg5 cc-connect up to and including version 1.4.1. The affected product is identified by the cpe:2.3:a:chenhg5:cc-connect. Any environment running the Management API in those versions is at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The EPSS score of 2% indicates a low exploitation probability, and the vulnerability is not listed in CISA KEV. The publicly available exploit shows that the attack can be initiated remotely through the Management API. As the vulnerability is an OS command injection, an attacker can achieve remote code execution with no local privileges.
OpenCVE Enrichment