Description
A security vulnerability has been detected in webgjc web_robot 2.4.0/2.5.0/2.8.0. The affected element is the function controller_listen/controller_recover of the file py/web.py. The manipulation of the argument case_name leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: 2.4% Low
KEV: No
Impact: Remote Code Execution via OS Command Injection
Action: Immediate Patch
AI Analysis

Impact

A vulnerability exists in webgjc web_robot 2.4.0, 2.5.0, and 2.8.0 where the controller_listen and controller_recover functions in py/web.py allow manipulation of the case_name argument to inject operating commands. The flaw can be triggered remotely and the attacker can execute arbitrary commands, leading to full compromise of the host system. This fits CWE-77 (OS Command Injection) and CWE-78 (Improper Escape of Shell Metacharacters). The disclosed exploit demonstrates that the attack is feasible without local privileges.

Affected Systems

Affected vendors and products are webgjc web_robot. The product is vulnerable in versions 2.4.0, 2.5.0, and 2.8.0. No other affected versions are listed.

Risk and Exploitability

The CVSS score for this issue is 5.3, the EPSS score is 2%, and the vulnerability is not listed in CISA's KEV catalog. The description states that the attack can be initiated remotely using the exposed controller_recover endpoint. Given the lack of a public, widespread exploitation record, the likelihood of exploitation of this remote code‑execution vector warrants prompt action.

Generated by OpenCVE AI on September 15, 2026 at 17:58 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to a patched release of web_robot that fixes the command injection flaw
  • Restrict network access to the controller_recover endpoint and enforce strong authentication
  • Implement input validation or sanitization for the case_name field to prevent injection

Generated by OpenCVE AI on September 15, 2026 at 17:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in webgjc web_robot 2.4.0/2.5.0/2.8.0. The affected element is the function controller_listen/controller_recover of the file py/web.py. The manipulation of the argument case_name leads to os command injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Title webgjc web_robot web.py controller_recover os command injection
First Time appeared Webgjc
Webgjc web Robot
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:webgjc:web_robot:*:*:*:*:*:*:*:*
Vendors & Products Webgjc
Webgjc web Robot
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Webgjc Web Robot
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T15:48:56.296Z

Reserved: 2026-09-12T08:03:48.661Z

Link: CVE-2026-90492

cve-icon Vulnrichment

Updated: 2026-09-14T15:48:50.877Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T02:17:04.930

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90492

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T18:00:17Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')