Description
4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter, thereby executing arbitrary system commands on the server.
Published: 2026-08-24
Score: 9.3 Critical
EPSS: 1.5% Low
KEV: No
Impact: Remote Code Execution via OS Command Injection
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an OS Command Injection flaw in the 4MOSAn GCB Doctor application. An unauthenticated remote attacker can supply crafted inputs to an ADOdb test page parameter, causing arbitrary system commands to execute on the server. This flaw can lead to full compromise of the underlying operating system, data loss, and service disruption.

Affected Systems

4MOSAn Security Technology’s GCB Doctor product is affected. All installations running versions prior to 20260621 contain the vulnerable ADOdb test page. The original product name and vendor are 4MOSAn Security Technology and 4MOSAn GCB Doctor.

Risk and Exploitability

The CVSS score of 9.3 indicates critical severity. The EPSS score of 2% suggests a modest likelihood of exploitation, but the flaw permits remote execution without authentication, implying high likelihood of exploitation if the target is exposed. The vulnerability is not yet listed in the CISA KEV catalog. Attackers can simply send a crafted request to the exposed test page endpoint and achieve arbitrary command execution. Given the lack of authentication and the direct shell access, the risk to confidentiality, integrity, and availability is maximal.

Generated by OpenCVE AI on August 24, 2026 at 17:21 UTC.

Remediation

Vendor Solution

Upgrade to version 20260621 or later and perform the FreeBSD-GCB Management Center security upgrade.


OpenCVE Recommended Actions

  • Upgrade 4MOSAn GCB Doctor to version 20260621 or later and apply the FreeBSD‑GCB Management Center security upgrade as prescribed by the vendor.
  • Remove or disable the ADOdb test page and any unused test files to eliminate the injection vector.
  • Implement firewall or access control rules to restrict external access to the ADOdb test page endpoint until the patch is applied.

Generated by OpenCVE AI on August 24, 2026 at 17:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 24 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared 4mosan Security Technology
4mosan Security Technology 4mosan Gcb Doctor
Vendors & Products 4mosan Security Technology
4mosan Security Technology 4mosan Gcb Doctor

Mon, 24 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 24 Aug 2026 04:00:00 +0000

Type Values Removed Values Added
Description 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter, thereby executing arbitrary system commands on the server.
Title 4MOSAn Security Technology|4MOSAn GCB Doctor - OS Command Injection
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

4mosan Security Technology 4mosan Gcb Doctor
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-08-24T12:51:11.649Z

Reserved: 2026-08-24T02:02:23.438Z

Link: CVE-2026-78211

cve-icon Vulnrichment

Updated: 2026-08-24T12:50:48.605Z

cve-icon NVD

Status : Deferred

Published: 2026-08-24T04:16:59.493

Modified: 2026-08-26T16:40:21.650

Link: CVE-2026-78211

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-24T21:11:53Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')