Impact
The SGA1000 device contains an OS command injection flaw that allows an attacker who can log in to the product to inject and execute arbitrary operating‑system commands. This grants the attacker full control of the device, potentially compromising confidentiality, integrity, and availability.
Affected Systems
Contec Co., Ltd. SGA1000 devices are impacted. No specific affected version range is available in the CNA data or references. The flaw is reported to affect all variants of the SGA1000 as no further detail is provided.
Risk and Exploitability
The CVSS Base Score of 8.7 categorizes this vulnerability as high severity. The EPSS score of 1% indicates a low but non‑zero exploitation probability so no widespread exploitation has been reported yet. The vulnerability is not listed in CISA KEV, meaning it has not been identified as a known exploited vulnerability by CISA. The description infers that an authenticated session is required, so an attacker must first obtain valid login credentials or otherwise access the device's interface. Once authenticated, crafted inputs can trigger the vulnerable command execution path, allowing full compromise of the system.
OpenCVE Enrichment