Impact
A flaw in the traceroute action of Rapid7 InsightConnect’s Traceroute Plugin allows remote attackers to inject and execute arbitrary OS commands through the host, port, max_ttl, count, or time_out request parameters. The vulnerability stems from insufficient input validation when constructing shell commands, enabling attackers to run commands with the privileges of the InsightConnect service.
Affected Systems
The issue targets Rapid7 InsightConnect’s Traceroute Plugin, a component of the InsightConnect automation platform deployed on Linux environments. No specific affected version information is listed in the CVE record, so administrators should verify the plugin version in use against vendor documentation and upgrade if necessary.
Risk and Exploitability
The CVSS score of 7.7 indicates a high‑severity vulnerability. EPSS data is not available and the flaw is not part of the CISA KEV catalog, suggesting limited publicly known exploitation. However, because the attack vector is remote and operates via the traceroute action endpoint, a successful exploitation would grant attackers arbitrary command execution on the host, exposing the system to confidentiality, integrity, and availability risks.
OpenCVE Enrichment