Impact
NUMail, a product of Green-Computing, suffers from an OS Command Injection flaw that allows attackers who do not need to authenticate to supply crafted input that is directly passed to the operating system for execution. This vulnerability enables an attacker to run arbitrary shell commands on the server, giving them full control over the affected system and compromising its confidentiality, integrity and availability.
Affected Systems
The vulnerability affects Green-Computing’s NUMail email platform. Any instance running a version released before 202602162 is impacted; the vendor has issued a patch with version 202602162 or later that resolves the issue.
Risk and Exploitability
The CVSS score of 9.3 classifies the flaw as critical, and although no EPSS score is available, the flaw can be exploited remotely without authentication. The vulnerability is not listed in CISA KEV at present, but its high severity and clear attack path suggest a high likelihood of exploitation in the wild. Attackers can reach the vulnerable input via the publicly exposed service, enabling them to execute commands against the server swiftly.
OpenCVE Enrichment