CVE-2021-26752

HIGH

NeDi 1.9C - Authenticated OS Command Injection via Nodes Traffic md or ag Parameter

Title source: llm
STIX 2.1

Description

NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the md or ag HTTP GET parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.

References (1)

Core 1
Core References
Exploit, Third Party Advisory x_refsource_misc
https://n4nj0.github.io/advisories/nedi-multiple-vulnerabilities-i/

Scores

CVSS v3 8.8
EPSS 0.0149
EPSS Percentile 70.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-78
Status published
Products (1)
nedi/nedi 1.9c
Published Feb 12, 2021
Tracked Since Feb 18, 2026