{
    "id": "CVE-2012-5878",
    "published": "2020-01-03 20:15:11",
    "last_modified": "2026-06-16 23:47:30",
    "cvss_score": "9.8",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
    "cwe": "CWE-78",
    "description": "Bulb Security Smartphone Pentest Framework (SPF) 0.1.2 through 0.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in the hostingPath parameter to (1) SEAttack.pl or (2) CSAttack.pl in frameworkgui/ or the (3) appURLPath parameter to frameworkgui/attachMobileModem.pl.",
    "epss_score": "0.09296",
    "epss_percentile": "0.95207",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 1,
    "updated_at": "2026-09-27 18:17:11",
    "priority": {
        "rank": 2,
        "label": "Patch early",
        "why": "A public exploit exists."
    },
    "products": [
        {
            "vendor": "bulbsecurity",
            "product": "smartphone_pentest_framework"
        }
    ],
    "kev_detail": null,
    "exploits": [
        {
            "source": "exploit-db",
            "ref_id": "38114",
            "title": "Smartphone Pentest Framework - Multiple Remote Command Execution Vulnerabilities",
            "date": "2012-12-10",
            "url": "https://www.exploit-db.com/exploits/38114"
        }
    ],
    "refs_list": [
        "https://www.htbridge.com/advisory/HTB23123",
        "https://www.htbridge.com/advisory/HTB23127",
        "https://www.htbridge.com/advisory/HTB23123",
        "https://www.htbridge.com/advisory/HTB23127"
    ]
}