CVE-2026-23759
7.2Perle Systems · IOLAN STS/SCS
Perle IOLAN STS and SCS terminal servers are vulnerable to authenticated OS command injection via the restricted shell, allowing root-level command execution.
Executive summary
A critical authentication-based command injection vulnerability in Perle IOLAN STS and SCS terminal servers allows an attacker to achieve full root-level compromise of the affected devices.
Vulnerability
This is an OS Command Injection (CWE-78) vulnerability occurring within the restricted shell of the terminal server. An attacker with authenticated access can exploit insufficient argument sanitization in the 'ps' command to execute arbitrary code as root.
Business impact
Successful exploitation results in full system compromise, granting an attacker root privileges on the terminal server. Given the nature of these devices as infrastructure components, this could lead to network traffic interception, unauthorized lateral movement, or complete loss of administrative control, justifying the CVSS score of 7.2.
Remediation
Immediate Action: Update all affected Perle IOLAN STS and SCS units to firmware version 6.0 or later immediately.
Proactive Monitoring: Review device access logs for unusual shell commands or unexpected attempts to invoke the 'ps' utility with complex arguments.
Compensating Controls: Restrict management interface access to trusted network segments and enforce strong, unique administrative credentials to prevent unauthorized authentication.
Exploitation status
Public Exploit Available: Yes, a technical write-up detailing the vulnerability and exploitation mechanism is available via the VulnCheck advisory referenced in the official record.
Analyst recommendation
The severity of this vulnerability, combined with the potential for full system takeover, necessitates an immediate patching cycle. Organizations should prioritize updating all deployed IOLAN STS and SCS hardware to version 6.0 to eliminate the injection vector and secure the administrative shell.
Sources
Originally found and disclosed by Victor A. Morales, Senior Pentester Team Leader, GM Sectec, Corp., Omar Crespo, Pentester, GM Sectec, Corp., with VulnCheck (coordinator), per the CVE Program record.