Impact
The vulnerability is an insecure deserialization flaw that allows unauthenticated remote attackers to execute arbitrary code on the servers hosting OAKlouds. By sending maliciously crafted serialized payloads, an attacker can take full control of the system, enabling persistence and data theft. This weakness is classified as CWE‑502, indicating unsafe handling of serialized data.
Affected Systems
HGiga’s OAKlouds custom_page modules version 2.0, 3.0 and 4.0 are affected. All releases prior to 26 of each major version lack the necessary protection. The vendor recommends updating to version 26 or later to remediate the issue.
Risk and Exploitability
The CVSS score of 9.3 signifies critical severity. The EPSS score of less than 1 % suggests that exploitation is currently unlikely, and the vulnerability is not in the CISA KEV catalog. The attack vector is inferred to be remote and unauthenticated, relying on the deserialization endpoint to process attacker‑supplied data, which permits remote code execution if the server accepts the payload. Because the flaw can be triggered without authentication, the potential impact is system‑wide compromise should an attacker be able to reach the affected endpoint.
OpenCVE Enrichment