ConfigServer 安全与防火墙(CSF)中,由于请求 URL 的转义处理不当,未经身份验证的远程攻击者可通过 shell 命令注入漏洞,以 CSF 服务账户的身份执行任意命令。 该漏洞影响由 ConfigServer 原始分发的软件版本,以及包含易受攻击代码的、由 WebPros 维护的分支版本。WebPros 已在 16.30 版本中修复了此漏洞。其他分支或独立维护的 ConfigServer 安全与防火墙(CSF)版本也可能受到影响,应单独进行评估。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WebPros | ConfigServer Security & Firewall | 14.00 ~ 16.30 | - |
|
| ConfigServer | ConfigServer Security & Firewall | 14.00 ~ * | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-65639 | 9.5 CRITICAL | ConfigServer Security & Firewall 16.30以下OS命令注入 |
| CVE-2026-68488 | Plesk 竞争条件致本地提权 | |
| CVE-2026-68487 | Plesk Backup Manager 路径遍历致root任意文件写入 |
No comments yet