CVE-2024-26260

CRITICAL

HGiga OAKlouds 2.0/3.0 < 188 & WebBase 2.0/3.0 < 1051 - OS Command Injection

Title source: llm
STIX 2.1

Description

The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request parameters. This enables the execution of arbitrary code on the remote server without permission.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://www.twcert.org.tw/tw/cp-132-7673-688b7-1.html

Scores

CVSS v3 9.8
EPSS 0.0160
EPSS Percentile 72.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (4)
hgiga/oaklouds-organization-2.0 < 188
hgiga/oaklouds-organization-3.0 < 188
hgiga/oaklouds-webbase-2.0 < 1051
hgiga/oaklouds-webbase-3.0 < 1051
Published Feb 15, 2024
Tracked Since Feb 18, 2026