关键漏洞信息 标题: meterN 1.2.3 Authenticated Remote Code Execution via Admin Scripts 严重性: HIGH 日期: December 31, 2025 受影响版本: meterN 1.2.3 and 0.8.3.2 CVE编号: CVE-2021-47747 CWE编号: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') CVSS评分: 8.8 CVSS向量: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/SC:H/CI:H/II:H/E:P/RL:O/RC:C/CR:H/IR:H/MAV:N/MAC:L/MPR:H/MUI:N/MC:H/MS:N 参考文献: - ExploitDB-50596 - Archived Vendor Homepage - Zero Science Lab Disclosure (ZSL-2021-5690) 发现者: LiquidWorm as Gjoko Krstic of Zero Science Lab 描述: meterN 1.2.3 contains an authenticated remote code execution vulnerability in admin_meter2.php and admin_indicator2.php scripts. Attackers can exploit the 'COMMANDx' and 'LIVECOMMANDx' POST parameters to execute arbitrary system commands with administrative privileges.