CVE-2019-25243

FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' paramete...

high 8.8 CVSS 3.1
Published: Dec 24, 2025
Modified: Dec 30, 2025
Vendor: Iwt
Product: Facesentry Access Control System Firmware
Versions: 5.7.0,5.7.2,6.4.8

Description

FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters.

References

Related CVEs