Easywall 0.3.1 allows authenticated remote command...
High severity
Unreviewed
Published
Dec 4, 2025
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Dec 4, 2025
Published to the GitHub Advisory Database
Dec 4, 2025
Easywall 0.3.1 allows authenticated remote command execution via a command injection vulnerability in the /ports-save endpoint that suffers from a parameter injection flaw. Attackers can inject shell metacharacters to execute arbitrary commands on the server.
References