PT-2020-17155 · Zeroshell · Zeroshell

CVE-2020-29390

·

Published

2020-11-30

·

Updated

2025-07-16

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zeroshell version 3.9.3
Description The issue allows an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character in the /cgi-bin/kerbynet API endpoint, specifically through the StartSessionSubmit parameter.
Recommendations For Zeroshell version 3.9.3, consider disabling access to the /cgi-bin/kerbynet API endpoint or restricting the use of the StartSessionSubmit parameter until a patch is available. Avoid using shell metacharacters and the %0a character in the StartSessionSubmit parameter to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-29390

Affected Products

Zeroshell