PT-2026-25145 · Git+2 · Thingino-Firmware+1

Azmi Alsarayrah

·

Publicado

2026-03-13

·

Atualizado

2026-03-26

·

CVE-2026-22209

CVSS v3.1

8.8

Alta

VetorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions thingino-firmware versions prior to commit e3f6a41 wpDiscuz versions prior to 7.6.47
Description thingino-firmware contains an unauthenticated operating system command injection issue in the WiFi captive portal CGI script. This allows remote attackers to execute arbitrary commands as root by injecting malicious code through unsanitized HTTP parameter names. Attackers can exploit the eval function in the parse query() and parse post() functions to achieve remote code execution and perform privileged configuration changes, including root password reset and SSH authorized keys modification, resulting in full persistent device compromise.
wpDiscuz contains a cross-site scripting issue in the customCss field. Administrators can inject malicious scripts by breaking out of style tags. Attackers with admin access can inject payloads to execute arbitrary JavaScript in user browsers.
Recommendations thingino-firmware versions prior to commit e3f6a41: Update to commit e3f6a41 or later. wpDiscuz versions prior to 7.6.47: Update to version 7.6.47 or later.

Correção

OS Command Injection

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-22209

Produtos afetados

Thingino-Firmware
Wpdiscuz