CVE-2012-5878 EXPLOIT
9.8
CRITICAL · CVSS 3.1 · EPSS 9.3% (pctl 95)
Patch early
A public exploit exists.
Description
Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in frameworkgui/ or the (3) appURLPath parameter to frameworkgui/attachMobileModem.pl.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 9.3% — more likely to be exploited than 95% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2020-01-03 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| bulbsecurity | smartphone pentest framework |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Smartphone Pentest Framework - Multiple Remote Command Execution Vulnerabilities | 2012-12-10 |
References
→ the Explorer · watch your stack · NVD