This is a summary of the AI-generated 10-question deep analysis. The full version (longer answers, follow-up Q&A, related CVEs) requires login.
Read the full analysis โ
Q1What is this vulnerability? (Essence + Consequences)
๐จ **Essence**: OS Command Injection in TOPSEC TopACM. <br>๐ฅ **Consequences**: Attackers can execute arbitrary system commands on the target server.โฆ
๐ **Privileges**: The injected commands likely execute with the privileges of the web service account (often root or high-privilege user in such appliances).โฆ
โก **Threshold**: **LOW**. <br>๐ **Auth**: CVSS Vector `PR:N` indicates **No Privileges Required**. <br>๐ **Access**: `AV:N` means it is exploitable over the **Network**.โฆ
๐ข **Public Exploit**: Yes. <br>๐ **Evidence**: References include a Feishu doc tagged as 'exploit' and VDB entries (VDB-351077) detailing the HTTP request for `nmc_sync.php`.โฆ
๐ **Self-Check**: <br>1. Scan for the specific endpoint: `/view/systemConfig/management/nmc_sync.php`. <br>2. Look for HTTP requests containing the `template_path` parameter. <br>3.โฆ
๐ฉน **Official Fix**: The data implies a fix is available or advisory is issued (VDB submission exists). <br>๐ **Action**: Contact Topsec support immediately.โฆ
๐ฅ **Urgency**: **CRITICAL**. <br>๐ **CVSS Score**: 9.8 (Critical). <br>โณ **Priority**: **Immediate Action Required**. <br>๐จ Since it is unauthenticated and remote, automated scanners and bots will likely target this.โฆ