A shell command injection in the HW Events SNMP community in XoruX LPAR2RRD and STOR2RRD before 7.30 allows authenticated remote attackers to execute arbitrary shell commands as the user running the service.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HXorux Lpar2rrd
APPXorux< 7.30Xorux Stor2rrd
APPXorux< 7.30
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
Related vulnerabilities
CVE-2021-42371CRITICAL9.8PL ✓same product
Hardkodowane konto systemowe w XoruX LPAR2RRD i STOR2RRD
CVE-2020-24032CRITICAL9.8PL ✓same product
Command injection w XoruX LPAR2RRD i STOR2RRD przez parametr strefy czasowej
CVE-2014-4981CRITICAL9.8PL ✓same product
Command Injection w LPAR2RRD — zdalne wykonanie poleceń systemowych
CVE-2014-4982CRITICAL9.8PL ✓same product
Command injection w Xorux LPAR2RRD — zdalne wykonanie poleceń
CVE-2025-54769HIGH8.8same product
An authenticated, read-only user can upload a file and perform a directory traversal to have the uploaded file...