CVE-2012-10041 - CVE House
Back to Database
Status published Critical CVE-2012-10041

WAN Emulator v2.3 Command Execution

Vulnerability Description

WAN Emulator v2.3 contains two unauthenticated command execution vulnerabilities. The result.php script calls shell_exec() with unsanitized input from the pc POST parameter, allowing remote attackers to execute arbitrary commands as the www-data user. The system also includes a SUID-root binary named dosu, which is vulnerable to command injection via its first argument. An attacker can exploit both flaws in sequence to achieve full remote code execution and escalate privileges to root.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-10041

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • bcoles

Affected Vendor

WAN Emulator

View all reports →

Affected Software

WAN Emulator
Vulnerable Versions:
2.3

Timeline

Official Publish: August 8th, 2025
Last Modified: April 7th, 2026
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)