14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.
The vulnerability is classified as CWE-94 (improper control of code generation) and affects the fingerprint function in the 14Finger application. An attacker can submit a specially crafted payload that is improperly processed by this function, resulting in execution of injected commands in the context of the application. The lack of authentication requirements and low attack complexity (AC:L, PR:N) make this vulnerability exceptionally easy to exploit.
An attacker can gain full control over the system by executing arbitrary commands — leading to disclosure of sensitive data and modification or deletion of system resources.
Apply patches available from the vendor according to references. It is recommended to monitor the project repository at https://github.com/b1ackc4t/14Finger for updates. Until a patch is released, consider restricting network access to the application.
B1Ackc4T 14Finger version 1.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NB1ackc4t 14finger
APPB1Ackc4T1.1
Related vulnerabilities
Nieautoryzowane usuwanie użytkowników w 14Finger v1.1
Insecure permissions in the component /api/admin/user of 14Finger v1.1 allows attackers to access all user inf...
Insecure permissions in 14Finger v1.1 allow attackers to escalate privileges from normal user to Administrator...