CVE-2019-12585

CRITICAL

Apcupsd < 2.4.4 - OS Command Injection

Title source: rule
STIX 2.1

Description

Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.

Scores

CVSS v3 9.8
EPSS 0.1149
EPSS Percentile 93.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (3)
apcupsd/apcupsd 0.3.91_5
netgate/pfsense 2.4.4 (4 CPE variants)
netgate/pfsense < 2.4.4
Published Jun 03, 2019
Tracked Since Feb 18, 2026