Rengine GitHub Repositoryproduct
https://github.com/yogeshojha/rengine CVE-2024-58287
HIGH
reNgine 2.2.0 Authenticated Command Injection via Scan Engine Configuration
Record summary
CVE-2024-58287 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that allows authenticated attackers to execute arbitrary commands. Attackers can modify the nmap_cmd parameter with malicious base64-encoded payloads to achieve remote code execution during scan engine configuration.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 18, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
reNgineBrowse rengine / reNgineDefault status: unaffected | CVE List | 2.2.0 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBreNgine 2.2.0 - Command Injection (Authenticated)ExploitDB exploitby Caner TercanNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-58287 Rengine Wiki Homepageproduct
https://rengine.wiki/ ExploitDB-52081exploit
https://www.exploit-db.com/exploits/52081 VulnCheck Advisory: reNgine 2.2.0 Authenticated Command Injection via Scan Engine ConfigurationThird-party advisory
https://www.vulncheck.com/advisories/rengine-authenticated-command-injection-via-scan-engine-configuration