CWE-78:存在“操作系统命令注入”漏洞(即用于操作系统命令的专用元素中和不当)。当启用了 SSH 的已认证用户与操作系统控制台交互时,如果控制台未能正确处理用户可控的输入,可能会导致权限提升至 root,并允许非授权执行管理功能。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Schneider Electric | PowerLogic T300 | Versions 2.9.8-5620 and prior | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-8044 | 8.6 HIGH | CWE-88: 特权账户下备份配置参数命令注入 |
| CVE-2026-19233 | 8.6 HIGH | CWE-918:服务器请求伪造(SSRF)漏洞 |
No comments yet