Impact
The vulnerability is an OS Command Injection flaw in the 4MOSAn GCB Doctor application. An unauthenticated remote attacker can supply crafted inputs to an ADOdb test page parameter, causing arbitrary system commands to execute on the server. This flaw can lead to full compromise of the underlying operating system, data loss, and service disruption.
Affected Systems
4MOSAn Security Technology’s GCB Doctor product is affected. All installations running versions prior to 20260621 contain the vulnerable ADOdb test page. The original product name and vendor are 4MOSAn Security Technology and 4MOSAn GCB Doctor.
Risk and Exploitability
The CVSS score of 9.3 indicates critical severity. The EPSS score of 2% suggests a modest likelihood of exploitation, but the flaw permits remote execution without authentication, implying high likelihood of exploitation if the target is exposed. The vulnerability is not yet listed in the CISA KEV catalog. Attackers can simply send a crafted request to the exposed test page endpoint and achieve arbitrary command execution. Given the lack of authentication and the direct shell access, the risk to confidentiality, integrity, and availability is maximal.
OpenCVE Enrichment