Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-12104— Authenticated OS Command Injection in Bondix

AI Predicted 8.8 Difficulty: Easy EPSS 1.32% · P68

Affected Version Matrix 2

VendorProductVersion RangeStatus
SIMA GmbHBondix Server≤ 1.25.7.5affected
1.25.7.6unaffected
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2026-12104

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Authenticated OS Command Injection in Bondix
Source: CVE Program / CVE List V5
Vulnerability Description
OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.7.5 on Linux allows an authenticated attacker with configuration write access to execute arbitrary operating-system commands via crafted configuration values passed to server-side scripts.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/AU:Y/R:U/RE:L/U:Amber
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5
Vulnerability Title
SIMA GmbH Bondix Server 命令注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
SIMA GmbH Bondix Server是SIMA GmbH公司的一款部署在云端或数据中心的服务器端软件,它能将来自多条互联网线路的流量汇聚成一条稳定、高速且可靠的单一网络连接。 SIMA GmbH Bondix Server 1.25.7.5及之前版本存在命令注入漏洞,该漏洞源于环境和隧道配置功能存在OS命令注入,配置写入权限的攻击者可能通过特制的配置值执行任意操作系统命令。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
SIMA GmbHBondix Server 0 ~ 1.25.7.5 -

II. Public POCs for CVE-2026-12104

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-12104

登录查看更多情报信息。

Vendor Advisories for CVE-2026-12104 (1)

Vendor Pages for CVE-2026-12104 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-12104

No comments yet


Leave a comment