CVE-2026-53611
9.8AS203038 · looking-glass
A critical OS command injection vulnerability exists in the Looking Glass network-diagnostic platform due to improper input validation, allowing unauthenticated remote code execution.
Executive summary
An unauthenticated OS command injection vulnerability in AS203038 Looking Glass allows remote attackers to execute arbitrary system commands, posing a critical risk to the host environment.
Vulnerability
The application fails to properly sanitize input via an unanchored regular expression in its validation layer, which can be exploited by an unauthenticated attacker to inject and execute arbitrary OS commands.
Business impact
This vulnerability carries a CVSS score of 9.8, reflecting its potential for full system compromise. Successful exploitation grants an attacker complete control over the host running the looking-glass service, which may lead to unauthorized access to connected network infrastructure, sensitive configuration data, and potential lateral movement within the network.
Remediation
Immediate Action: Upgrade AS203038 looking-glass to version 1.3.5 or later immediately to apply the necessary input validation fixes.
Proactive Monitoring: Review system and application logs for unusual process execution patterns or unexpected shell commands originating from the looking-glass service.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules designed to detect and block OS command injection attempts directed at the gRPC API or web interface.
Exploitation status
Public Exploit Available: No — no confirmed public exploit exists in the provided data.
Analyst recommendation
The severity of this flaw necessitates immediate attention. Organizations utilizing the looking-glass platform must prioritize the update to version 1.3.5 to remediate the OS command injection vulnerability. Failure to patch leaves the underlying infrastructure exposed to complete system takeover by remote, unauthenticated actors.