PT-2026-7598 · Metis Dfs · Metis Dfs
Or Balog
·
Publicado
2026-02-11
·
Atualizado
2026-02-11
·
CVE-2026-2249
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
METIS DFS versions prior to oscore 2.1.234-r18
Description
METIS DFS devices expose a web-based shell at the
/console endpoint that does not require authentication. Accessing this endpoint allows a remote attacker to execute arbitrary operating system commands with 'daemon' privileges, resulting in the compromise of the software and granting unauthorized access to modify configuration, read and alter sensitive data, or disrupt services.Recommendations
For versions prior to oscore 2.1.234-r18, restrict access to the
/console endpoint.
For versions prior to oscore 2.1.234-r18, disable the web-based shell if it is not required.Correção
Missing Authentication
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Metis Dfs