216.73.217.22

CVE-2012-10039

· Published 11/08/2025 15:15 · Modified 11/08/2025 18:32

Labels: CVE-2012-10039 2025-08-11CVE-2012-10039CWE-78[email protected]

Essential information

Published
11/08/2025 15:15
Modified
11/08/2025 18:32
Author
Creator
CVSS
9.4 CRITICAL (v3) 9.4 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

ZEN Load Balancer versions 2.0 and 3.0-rc1 contain a command injection vulnerability in content2-2.cgi. The filelog parameter is passed directly into a backtick-delimited exec() call without sanitation. An authenticated attacker can inject arbitrary shell commands, resulting in remote code execution as the root user. ZEN Load Balancer is the predecessor of ZEVENET and SKUDONET. The affected versions (2.0 and 3.0-rc1) are no longer supported. SKUDONET CE is the current community-maintained successor.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
zen / zen load balancer cpe:2.3:a:zen:zen_load_balancer:2.0-3.0-rc1:*:*:*:*:*:*:*

References