CVE-2026-65639
9.5WebPros · ConfigServer Security & Firewall
An OS command injection vulnerability in the ConfigServer Security & Firewall rule parser allows unauthenticated remote attackers to execute arbitrary commands as root via malicious rule feeds.
Executive summary
A critical OS command injection vulnerability in ConfigServer Security & Firewall allows unauthenticated remote attackers to achieve full system compromise with root privileges.
Vulnerability
This vulnerability is an OS command injection (CWE-78) occurring within the advanced rule parser of the firewall. It allows an unauthenticated remote attacker who controls a configured allow or deny feed to inject and execute arbitrary system commands with root-level permissions.
Business impact
The potential for unauthenticated remote code execution with root privileges represents a total compromise of the affected server. Given the CVSS score of 9.5, this vulnerability enables an attacker to gain full control over the host, leading to complete data exfiltration, persistent malware installation, and widespread disruption of security services.
Remediation
Immediate Action: Update the WebPros ConfigServer Security & Firewall installation to version 16.30 or later immediately.
Proactive Monitoring: Review system logs and firewall rule feed configurations for any unexpected or unauthorized modifications to allow or deny lists.
Compensating Controls: Implement strict egress filtering to prevent the firewall from reaching untrusted or unknown external feed sources until the patch is applied.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Due to the critical nature of this vulnerability and the potential for total system takeover, immediate patching is required. Administrators should verify their current version and upgrade to 16.30 without delay to eliminate the risk of remote command execution.
More WebPros CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section