CVE-2025-34035
CRITICAL 10.0EPSS 12.3%
An OS command injection vulnerability exists in EnGenius EnShare Cloud Service version 1.4.11 and earlier. The usbinteract.cgi script fails to properly sanitize user input passed to the path parameter, allowing unauthenticated remote attackers to inject arbitrary shell commands. The injected commands are executed with root privileges, leading to full system compromise.
- CVSS v4.0
- 10.0 CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 12.33% chance of exploitation in the next 30 days, 96th percentile
- Nuclei
- critical · CWE-78
- Published
- 2025-06-24
- Updated
- 2026-04-07
Proof-of-concept exploits (4)
- https://www.exploit-db.com/exploits/42114
- https://www.zeroscience.mk/en/vulnerabilities/ZSL-2017-5413.php
- https://packetstormsecurity.com/files/142792
- https://cxsecurity.com/issue/WLB-2017060050