rootpwn

critical · CVSS v3 8.8 · CVSS v4 8.6 · EPSS 0.02173

CVE-2026-15027

CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce …

Description

CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary OS commands through the local service interface, resulting in command execution on the victim's local computer.

Scores

Severity
critical
CVSS v2
10
CVSS v3
8.8
CVSS v4
8.6
EPSS
0.02173

← All CVEs