CVE-2015-2857

CRITICAL

Accellion File Transfer Appliance < 9_11_200 - Remote Code Execution via oauth_token Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2015-2857. PoCs published by Metasploit, hdm, including Metasploit module exploits/linux/http/accellion_fta_getstatus_oauth.

AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in Accellion FTA by injecting shell metacharacters into the 'oauth_token' parameter, leading to remote code execution. The exploit targets the '/tws/getStatus' endpoint and confirms vulnerability via a check method.

Description

Accellion File Transfer Appliance before FTA_9_11_210 allows remote attackers to execute arbitrary code via shell metacharacters in the oauth_token parameter.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotehardware
https://www.exploit-db.com/exploits/37597

This Metasploit module exploits a command injection vulnerability in Accellion FTA by injecting shell metacharacters into the 'oauth_token' parameter, leading to remote code execution. The exploit targets the '/tws/getStatus' endpoint and confirms vulnerability via a check method.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Accellion File Transfer Appliance (FTA) versions before FTA_9_11_210
No auth needed
Prerequisites: Network access to the target's HTTPS service (port 443)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by hdm · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/accellion_fta_getstatus_oauth.rb

This Metasploit module exploits a command injection vulnerability in Accellion FTA by injecting shell metacharacters into the 'oauth_token' parameter, which is passed to a system() call. The exploit targets the '/tws/getStatus' endpoint and achieves remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Accellion File Transfer Appliance (FTA) versions up to FTA_9_11_200
No auth needed
Prerequisites: Network access to the target's '/tws/getStatus' endpoint
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (4)

Core 4

Scores

CVSS v3 9.8
EPSS 0.8670
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-77
Status published
Products (1)
accellion/file_transfer_appliance < 9_11_200
Published Aug 22, 2017
Tracked Since Feb 18, 2026