CVE-2026-40456

An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de due to an IP address parameter being passed to the "exec()" function without proper validation, allowing attackers to execute arbitrary operating system commands.
CVSS

No CVSS.

Configurations

No configuration.

History

18 Jun 2026, 14:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-18 14:17

Updated : 2026-06-22 17:49


NVD link : CVE-2026-40456

Mitre link : CVE-2026-40456

CVE.ORG link : CVE-2026-40456


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')