Impact
A vulnerability exists in webgjc web_robot 2.4.0, 2.5.0, and 2.8.0 where the controller_listen and controller_recover functions in py/web.py allow manipulation of the case_name argument to inject operating commands. The flaw can be triggered remotely and the attacker can execute arbitrary commands, leading to full compromise of the host system. This fits CWE-77 (OS Command Injection) and CWE-78 (Improper Escape of Shell Metacharacters). The disclosed exploit demonstrates that the attack is feasible without local privileges.
Affected Systems
Affected vendors and products are webgjc web_robot. The product is vulnerable in versions 2.4.0, 2.5.0, and 2.8.0. No other affected versions are listed.
Risk and Exploitability
The CVSS score for this issue is 5.3, the EPSS score is 2%, and the vulnerability is not listed in CISA's KEV catalog. The description states that the attack can be initiated remotely using the exposed controller_recover endpoint. Given the lack of a public, widespread exploitation record, the likelihood of exploitation of this remote code‑execution vector warrants prompt action.
OpenCVE Enrichment