FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters.
Metrics
Affected Vendors & Products
References
History
Fri, 26 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 24 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters. | |
| Title | FaceSentry 6.4.8 Authenticated Remote Command Injection via Ping Test | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-12-24T19:27:58.965Z
Updated: 2025-12-24T20:23:05.664Z
Reserved: 2025-12-24T14:27:12.476Z
Link: CVE-2019-25243
Updated: 2025-12-24T20:03:50.105Z
Status : Received
Published: 2025-12-24T20:15:52.310
Modified: 2025-12-24T21:16:02.200
Link: CVE-2019-25243
No data.