CVE-2026-3821

SMCI · X14DBG-DAP, X14DBI

SMCI SMASH services on specific hardware models contain an OS command injection vulnerability that allows authenticated attackers to execute arbitrary code.

Executive summary

Authenticated attackers can execute arbitrary code on SMCI X14DBG-DAP and X14DBI hardware via an OS command injection vulnerability.

Vulnerability

The SMASH service improperly neutralizes special elements in OS commands, enabling authenticated users to perform command injection and achieve arbitrary code execution.

Business impact

An attacker with authenticated access can leverage this vulnerability to take full control of the affected BMC or IPMI hardware. This level of access allows for persistent system compromise, potentially impacting the entire server infrastructure managed by the affected boards, warranting the high CVSS score of 8.8.

Remediation

Immediate Action: Apply the vendor-provided security updates available through the official Supermicro support portal.

Proactive Monitoring: Monitor BMC/IPMI logs for anomalous command execution or administrative activity that deviates from established baselines.

Compensating Controls: Ensure that management interfaces are restricted to isolated management networks and are not exposed to the public internet.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Administrators must verify the firmware versions on the affected hardware and apply the required security patches immediately. Failure to secure management interfaces can lead to severe operational and security compromises across the server fleet.