CVE-2026-48097

0x5t4l1n · NexTOR_IP_CHANGER

NexTOR_IP_CHANGER versions before 2.0.0 contain vulnerabilities including OS command injection and NULL pointer dereference, allowing local users to execute arbitrary commands or cause crashes.

Executive summary

An OS command injection and NULL pointer dereference vulnerability in NexTOR_IP_CHANGER allows local authenticated users to compromise system integrity and availability.

Vulnerability

The software suffers from CWE-78 (OS Command Injection) and CWE-476 (NULL Pointer Dereference). These flaws permit a local user with low privileges to execute arbitrary system commands, potentially leading to a full system compromise.

Business impact

By allowing an attacker to inject OS commands, this vulnerability provides a pathway to escalate privileges and gain control over the local system. Given the CVSS score of 7.8, the ability to crash the service via NULL pointer dereference or execute commands poses a significant risk to the availability and security of the host machine.

Remediation

Immediate Action: Update NexTOR_IP_CHANGER to version 2.0.0 or later immediately.

Proactive Monitoring: Audit local system logs for unauthorized command execution or unexpected service terminations.

Compensating Controls: Restrict local access to the machine and limit the execution permissions of users who do not require access to the NexTOR_IP_CHANGER utility.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Users of the NexTOR_IP_CHANGER tool must upgrade to version 2.0.0 to remediate these critical flaws. The combination of command injection and potential service disruption makes this software a high-risk component on any system where it is installed. Immediate patching is strongly advised to prevent exploitation by malicious local users.