Showing 2 vulnerabilities on this page for [OSGi

Signals CISA KEV Ransomware Nuclei
equinox vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Eclipse Equinox OSGi 3.7.2 Remote Code Execution via Console

Eclipse Equinox OSGi 3.7.2 and earlier contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by sending payloads to the console interface. Attackers can connect to the OSGi console port and send base64-encoded bash commands wrapped in fork directives to achieve code execution and establish reverse shell connections.

CWE-306May 5, 2026
CVSS9.3v4.0EPSS0.55%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Eclipse Equinox OSGi 3.8-3.18 Console Remote Code Execution

Eclipse Equinox OSGi versions 3.8 through 3.18 contain a remote code execution vulnerability in the console interface that allows unauthenticated attackers to execute arbitrary code by exploiting the fork command functionality. Attackers can establish a telnet connection to the OSGi console, perform a telnet handshake, and send fork commands to download and execute malicious Java code, establishing a reverse shell connection.

CWE-306May 5, 2026
CVSS9.3v4.0EPSS0.455%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX