Impact
This vulnerability arises in the /adminPage/main/autoUpdate endpoint of cym1102 nginxWebUI. By manipulating the url parameter, an attacker can inject arbitrary code into the autoUpdate method, leading to remote code execution on the web server. The weakness maps to CWE-74 and CWE-94.
Affected Systems
vulnerable versions of cym1102 nginxWebUI up to 4.4.2 are affected. No later versions have been identified as impacted. The problem exists in the open source project hosted at the specifiedHub repository.
Risk and Exploitability
The CVSS base score of 5.3 indicates medium severity. The EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog. Remote exploitation is possible; the publicly disclosed exploit confirms that code injection can be achieved through the autoUpdate endpoint. Until a patch is merged, the technical feasibility and medium risk warrant monitoring and mitigation steps.
OpenCVE Enrichment