Showing 1 vulnerability on this page for VA MAX

Signals CISA KEV Ransomware Nuclei
VA MAX vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

VA MAX 8.3.4 Remote Code Execution via changeip.php

VA MAX 8.3.4 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the mtu_eth0 parameter. Attackers can send POST requests to the changeip.php endpoint with malicious payload in the mtu_eth0 field to execute commands as the apache user.

CWE-22Apr 5, 2026
CVSS8.7v4.0EPSS0.657%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX