Impact
The vulnerability is an OS command injection flaw caused by improper neutralization of special characters that are later passed to the operating system. An attacker who can authenticate to the device can supply crafted input and cause the device to execute arbitrary OS commands, potentially compromising system control or data.
Affected Systems
Contec FX series devices are affected, including FXA3000, FXA3020, FXA3200, FXA5020, FXE3000, FXE4000, FXE5000, FXS300, FXS4000, FXS4020, FXS5000 and FXS5021 models and their variant designations such as FXA3000-[][], FXA3020-[][], FXA5000-[][], FXA5020-[][], FXE3000‑WP, FXE3000‑[][], FXE4000‑WP, FXE5000‑[][] and FXS300[]‑CN. No specific firmware or hardware version information is provided, so all current releases of these models are potentially vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability. The EPSS score of 1% shows a low but non‑zero probability of exploitation in the wild. The device is not listed in the CISA KEV catalog. Exploitation requires an authenticated session; the attacker must first obtain valid credentials before injecting malicious input that triggers the command injection.
OpenCVE Enrichment