Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vulnerability in the Managed Ethernet Switch, resulting in full system compromise.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://certvde.com/de/advisories/VDE-2026-038 |
|
History
Tue, 16 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vulnerability in the Managed Ethernet Switch, resulting in full system compromise. | |
| Title | Command Injection via name parameter | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-06-16T08:18:02.856Z
Reserved: 2026-04-02T10:13:27.443Z
Link: CVE-2026-5416
No data.
Status : Deferred
Published: 2026-06-16T10:16:28.857
Modified: 2026-06-16T15:41:12.897
Link: CVE-2026-5416
No data.
OpenCVE Enrichment
No data.
Weaknesses