PT-2020-17155 · Zeroshell · Zeroshell

Published

2020-11-30

·

Updated

2025-07-16

·

CVE-2020-29390

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zeroshell version 3.9.3
Description The issue allows an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character in the /cgi-bin/kerbynet API endpoint, specifically through the StartSessionSubmit parameter.
Recommendations For Zeroshell version 3.9.3, consider disabling access to the /cgi-bin/kerbynet API endpoint or restricting the use of the StartSessionSubmit parameter until a patch is available. Avoid using shell metacharacters and the %0a character in the StartSessionSubmit parameter to minimize the risk of exploitation.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2020-29390

Affected Products

Zeroshell