A highly authenticated attacker can alter the config generator injecting a payload into future created configurations. The device is not correctly checking this configuration value before passing it to an system execute leading to code execution. This can result in a total loss of confidentiality, integrity and availability.
References
| Link | Resource |
|---|---|
| https://www.certvde.com/en/advisories/VDE-2026-054/ |
Configurations
No configuration.
History
27 May 2026, 09:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-27 09:16
Updated : 2026-05-27 14:53
NVD link : CVE-2026-40852
Mitre link : CVE-2026-40852
CVE.ORG link : CVE-2026-40852
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
