存在 CWE-88 漏洞(命令中的参数分隔符未被正确中和,即“参数注入”),攻击者若能通过特权账户提供恶意的备份配置参数,即可触发该漏洞并导致远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Schneider Electric | EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert) | Versions 9.1.2 and prior | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77120 | 8.7 HIGH | SSH控制台OS命令注入致提权 |
| CVE-2026-19233 | 8.6 HIGH | CWE-918:服务器请求伪造(SSRF)漏洞 |
No comments yet