CVE-2026-102256: OS Command Injection
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 appliance which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
Affected Software
Event History
Frequently Asked Questions
What level of access is required to exploit this issue?
The issue is post-authentication and the description identifies an authenticated attacker with administrator access as the potential attacker. Exploitation is only described as possible under specific conditions.
What could an attacker achieve if exploitation succeeds?
A successful attacker could execute arbitrary operating system commands on the SMA 1000 appliance. This could result in remote code execution with high impact to confidentiality, integrity, and availability.