Sceawere

Vulnerability Detail

CVE-2026-105134UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

AhsayCBS OS Command Injection Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
2h ago
Vendor
Ahsay
Product
AhsayCBS
Attack Type
OS Command Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve this issue. Upgrading the affected component is advised.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-10-04T07:16:33.480Z",
  "pubdate": "2026-10-04T07:16:33.480Z",
  "executiveSummary": "A critical OS command injection vulnerability exists within the Replication Receiver component of Ahsay AhsayCBS up to version 10.3.2. The flaw resides in the handling of user-supplied input via the 'random' argument within the '/rps/api/json/UpdateReceivers.do' endpoint.\nThis vulnerability allows an unauthenticated, remote attacker to execute arbitrary system commands with the privileges of the underlying application service. Successful exploitation poses a severe risk to the confidentiality, integrity, and availability of the host server.\nThe vulnerability is characterized by improper input sanitization, where malicious payloads injected into the 'random' parameter are executed directly by the server's operating system. Given the availability of public exploit code, the risk of active exploitation is significant.\nOrganizations using affected versions of AhsayCBS are at high risk of full system compromise. Immediate remediation is required to mitigate potential unauthorized access and post-exploitation activities such as data exfiltration or malware deployment.",
  "technicalDetails": "The vulnerability is an OS command injection flaw located in the Replication Receiver component of Ahsay AhsayCBS, specifically targeting the '/rps/api/json/UpdateReceivers.do' API endpoint. The root cause of this vulnerability is the failure of the application to properly sanitize or validate the 'random' parameter before passing it to system-level command execution functions.\nIn the affected versions (up to 10.3.2), the application insecurely concatenates user-controlled input from the 'random' argument into a system shell command string. Because the application logic does not implement robust input filtering or parameterization, an attacker can supply shell metacharacters (such as ';', '&', or '|') to break out of the intended command context and inject arbitrary commands.\nThe attack flow proceeds as follows: An attacker sends a crafted HTTP request to the target server, specifically targeting the /rps/api/json/UpdateReceivers.do endpoint. Within this request, the attacker manipulates the 'random' parameter to include a malicious payload, such as a shell command designed to perform reconnaissance, open a reverse shell, or modify system files. The server-side application processes this request and executes the injected string within the context of the application's process.\nBecause this endpoint is reachable remotely and does not appear to require stringent authentication, the barrier to exploitation is minimal. The impact is significant: upon successful command injection, the attacker operates with the same privilege level as the AhsayCBS service. This allows for full system control, including the ability to read sensitive configuration files, dump database credentials, install backdoors, or pivot into the internal network infrastructure.\nThe vulnerability affects all versions of Ahsay AhsayCBS up to and including 10.3.2. As there is existing proof-of-concept exploit code publicly available, the window of opportunity for attackers is active and ongoing. The vulnerability highlights a failure in secure coding practices related to system-level calls and highlights the critical necessity of using abstraction layers or strictly whitelisting allowed characters for API input parameters."
}
CVE-2026-105134: AhsayCBS OS Command Injection Vulnerability (CRITICAL Severity, CVSS: 10.0) | Sceawere