PT-2026-20937 · Rustfly · Rustfly

Indoushka

·

Published

2026-02-19

·

Updated

2026-02-20

·

CVE-2026-27476

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RustFly version 2.0.0
Description RustFly 2.0.0 contains a command injection issue in its remote UI control mechanism. The software accepts hex-encoded instructions over UDP port 5005 without proper sanitization. Attackers can send crafted hex-encoded payloads containing system commands to execute arbitrary operations on the target system. This includes the potential for reverse shell establishment and command execution. The vulnerable component accepts instructions via UDP port 5005.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-27476

Affected Products

Rustfly