Sceawere
Vulnerability Detail
CVE-2026-105134UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
AhsayCBS OS Command Injection Vulnerability
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 10
- Creation Date
- 2h ago
- Vendor
- Ahsay
- Product
- AhsayCBS
- Attack Type
- OS Command Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve this issue. Upgrading the affected component is advised.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "10.0",
"pubDate": "2026-10-04T07:16:33.480Z",
"pubdate": "2026-10-04T07:16:33.480Z",
"executiveSummary": "A critical OS command injection vulnerability exists within the Replication Receiver component of Ahsay AhsayCBS up to version 10.3.2. The flaw resides in the handling of user-supplied input via the 'random' argument within the '/rps/api/json/UpdateReceivers.do' endpoint.\nThis vulnerability allows an unauthenticated, remote attacker to execute arbitrary system commands with the privileges of the underlying application service. Successful exploitation poses a severe risk to the confidentiality, integrity, and availability of the host server.\nThe vulnerability is characterized by improper input sanitization, where malicious payloads injected into the 'random' parameter are executed directly by the server's operating system. Given the availability of public exploit code, the risk of active exploitation is significant.\nOrganizations using affected versions of AhsayCBS are at high risk of full system compromise. Immediate remediation is required to mitigate potential unauthorized access and post-exploitation activities such as data exfiltration or malware deployment.",
"technicalDetails": "The vulnerability is an OS command injection flaw located in the Replication Receiver component of Ahsay AhsayCBS, specifically targeting the '/rps/api/json/UpdateReceivers.do' API endpoint. The root cause of this vulnerability is the failure of the application to properly sanitize or validate the 'random' parameter before passing it to system-level command execution functions.\nIn the affected versions (up to 10.3.2), the application insecurely concatenates user-controlled input from the 'random' argument into a system shell command string. Because the application logic does not implement robust input filtering or parameterization, an attacker can supply shell metacharacters (such as ';', '&', or '|') to break out of the intended command context and inject arbitrary commands.\nThe attack flow proceeds as follows: An attacker sends a crafted HTTP request to the target server, specifically targeting the /rps/api/json/UpdateReceivers.do endpoint. Within this request, the attacker manipulates the 'random' parameter to include a malicious payload, such as a shell command designed to perform reconnaissance, open a reverse shell, or modify system files. The server-side application processes this request and executes the injected string within the context of the application's process.\nBecause this endpoint is reachable remotely and does not appear to require stringent authentication, the barrier to exploitation is minimal. The impact is significant: upon successful command injection, the attacker operates with the same privilege level as the AhsayCBS service. This allows for full system control, including the ability to read sensitive configuration files, dump database credentials, install backdoors, or pivot into the internal network infrastructure.\nThe vulnerability affects all versions of Ahsay AhsayCBS up to and including 10.3.2. As there is existing proof-of-concept exploit code publicly available, the window of opportunity for attackers is active and ongoing. The vulnerability highlights a failure in secure coding practices related to system-level calls and highlights the critical necessity of using abstraction layers or strictly whitelisting allowed characters for API input parameters."
}