FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters.
Metrics
Affected Vendors & Products
References
History
Wed, 24 Dec 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters. | |
| Title | FaceSentry 6.4.8 Authenticated Remote Command Injection via Ping Test | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-12-24T20:23:05.664Z
Reserved: 2025-12-24T14:27:12.476Z
Link: CVE-2019-25243
No data.
Status : Received
Published: 2025-12-24T20:15:52.310
Modified: 2025-12-24T21:16:02.200
Link: CVE-2019-25243
No data.
OpenCVE Enrichment
No data.