CVE-2026-78211: 4MOSAn Security Technology|4MOSAn GCB Doctor - OS Command Injection
4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter, thereby executing arbitrary system commands on the server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
4MOSAn GCB Doctorto a version that resolves this vulnerability.Fixed in 20260621
Event History
Frequently Asked Questions
Who can exploit this issue?
An unauthenticated remote attacker can exploit it. No credentials or user interaction are required.
What component is involved in exploitation?
The vulnerability is exposed through an ADOdb test page that was not removed. A malicious parameter supplied to that page can be used to inject operating-system commands.
What is the potential impact of successful exploitation?
Successful exploitation allows arbitrary system commands to be executed on the affected server. This can affect the confidentiality, integrity, and availability of the system.