peter bassill · operator
$ cve CVE-2018-14417 JSON

CVE-2018-14417 EXPLOIT

9.8
CRITICAL · CVSS 3.0 · EPSS 89.6% (pctl 100)

Patch early

A public exploit exists.

Description

A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' parameter from the snserv endpoint, allowing an unauthenticated attacker to execute arbitrary commands with root permissions.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS89.58% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVno
Public exploityes
Published2018-08-04
Last modified2026-06-17

Affected (1)

VendorProduct
softnascloud

Public exploits

SourceTitleDate
exploit-dbSoftNAS Cloud < 4.0.3 - OS Command Injection2018-07-27

References

→ the Explorer  ·  watch your stack  ·  NVD