Algo 8028 Control Panel - Remote Code Execution (RCE) (Authenticated)
Vulnerability Description
Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua endpoint that allows authenticated attackers to execute arbitrary commands. Attackers can exploit the insecure 'source' parameter by injecting commands that are executed with root privileges, enabling remote code execution through a crafted POST request.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-50909
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Filip Carlsson
Affected Vendor
Algo Solutions
View all reports →