CVE-2016-11017

CRITICAL

AKIPS Network Monitor 15.37-16.5 - Unauthenticated OS Command Injection via Username Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-11017. PoCs published by BrianWGray.

AI-analyzed exploit summary This exploit demonstrates an OS command injection vulnerability in AKIPS Network Monitor versions 15.37 through 16.5. The vulnerability allows an attacker to inject commands via the 'username' parameter during a failed login attempt, with the output returned in the login failure message.

Description

The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via shell metacharacters in the username parameter (a failed login attempt returns the command-injection output to a limited login failure field). This is fixed in 16.6.

Exploits (1)

exploitdb WORKING POC
by BrianWGray · textwebappsperl
https://www.exploit-db.com/exploits/39564

This exploit demonstrates an OS command injection vulnerability in AKIPS Network Monitor versions 15.37 through 16.5. The vulnerability allows an attacker to inject commands via the 'username' parameter during a failed login attempt, with the output returned in the login failure message.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: AKIPS Network Monitor 15.37-16.5
No auth needed
Prerequisites: Network access to the target application · Target application must be running a vulnerable version
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://ctrlu.net/vuln/0002.html
Exploit, Third Party Advisory, VDB Entry x_refsource_misc
https://www.exploit-db.com/exploits/39564

Scores

CVSS v3 9.8
EPSS 0.1944
EPSS Percentile 95.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
akips/network_monitor 15.37 - 16.5
Published Jan 06, 2020
Tracked Since Feb 18, 2026