CVE-2019-7276

CRITICAL EXPLOITED IN THE WILD NUCLEI

Optergy Enterprise and Proton < 2.3.0a - Remote Root Code Execution via Backdoor Console

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2019-7276 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 2 public exploits from researchers including LiquidWorm, including a Metasploit module exploits/linux/http/optergy_bms_backdoor_rce_cve_2019_7276. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit leverages an unauthenticated backdoor in Optergy BMS to execute arbitrary commands as root by bypassing authentication via a challenge-response mechanism. It sends a crafted POST request with a computed SHA1 and MD5 hash to achieve remote code execution.

Description

Optergy Proton/Enterprise devices allow Remote Root Code Execution via a Backdoor Console.

Exploits (2)

exploitdb WORKING POC
by LiquidWorm · pythonwebappshardware
https://www.exploit-db.com/exploits/47641

This exploit leverages an unauthenticated backdoor in Optergy BMS to execute arbitrary commands as root by bypassing authentication via a challenge-response mechanism. It sends a crafted POST request with a computed SHA1 and MD5 hash to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Optergy BMS <=2.3.0a (Proton and Enterprise)
No auth needed
Prerequisites: Network access to the target system · Target running affected Optergy BMS version
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/optergy_bms_backdoor_rce_cve_2019_7276.rb

This Metasploit module exploits an undocumented backdoor in Optergy Proton and Enterprise BMS (CVE-2019-7276) by leveraging a challenge-response mechanism to execute arbitrary commands as root via sudo. The exploit interacts with the Console.jsp backdoor script to achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Optergy Proton and Enterprise BMS versions 2.0.3a and below
No auth needed
Prerequisites: Network access to the target system on port 80 · The backdoor script (Console.jsp) must be accessible
devstral-2 · analyzed Feb 19, 2026 Full analysis →

Nuclei Templates (1)

Optergy Proton/Enterprise - Unauthenticated RCE via Backdoor Console
CRITICALby daffainfo
Shodan: html:"Optergy"

Scores

CVSS v3 9.8
EPSS 0.9338
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

VulnCheck KEV 2020-10-14
InTheWild.io 2021-10-14
Status published
Products (2)
optergy/enterprise < 2.3.0a
optergy/proton < 2.3.0a
Published Jul 01, 2019
Tracked Since Feb 18, 2026