216.73.217.22

CVE-2026-27476

· Published 19/02/2026 21:18 · Modified 20/02/2026 13:49

Labels: CVE-2026-27476 2026-02-19CVE-2026-27476CWE-78[email protected]

Essential information

Published
19/02/2026 21:18
Modified
20/02/2026 13:49
Author
Creator
CVSS
9.3 CRITICAL (v3) 9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

RustFly 2.0.0 contains a command injection vulnerability in its remote UI control mechanism that accepts hex-encoded instructions over UDP port 5005 without proper sanitization. Attackers can send crafted hex-encoded payloads containing system commands to execute arbitrary operations on the target system, including reverse shell establishment and command execution.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
rustfly / rustfly cpe:2.3:a:rustfly:rustfly:2.0.0:*:*:*:*:*:*:*

References