StoneFly storage concentrator是StoneFly公司的一种数据集中存储设备。 Stonefly Storage Concentrator 8.0.4.22之前版本存在命令注入漏洞,该漏洞源于debug.pl脚本中存在命令注入,远程攻击者可提交特制HTTP请求,因输入清理不当导致在底层系统上以root权限执行任意命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Stonefly | Storage Concentrator | < 8.0.4.22 |
affected |
8.0.4.29 |
unaffected | ||
| Stonefly | Storage Concentrator Virtual Machine | < 8.0.4.22 |
affected |
8.0.4.29 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Stonefly | Storage Concentrator | 0 ~ 8.0.4.22 | - |
|
| Stonefly | Storage Concentrator Virtual Machine | 0 ~ 8.0.4.22 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-56413 | 10.0 CRITICAL | OS Command Injection in StoneFly Storage Concentrator |
| CVE-2026-55721 | 9.3 CRITICAL | SQL Injection in StoneFly Storage Concentrator |
| CVE-2026-50110 | 9.2 CRITICAL | Use of Hard-coded Credentials in StoneFly Storage Concentrator |
| CVE-2026-50040 | 6.1 MEDIUM | Cross-site Scripting in StoneFly Storage Concentrator |
No comments yet