Zeroshell 3.9.0 Remote Command Execution

Vulnerability
An attacker can easily exploit this vulnerability by injecting OS commands into the web application if it does not properly sanitize its HTTP parameters. In Zeroshell 3.9.0, a Linux router, this vulnerability allows the attacker to execute code remotely.
Mitigation / Precaution
- Properly sanitize the parameters.
- We suggest you to update Zeroshell to a version greater than 3.9.2 in order to fix this vulnerability.
Summarize:
Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 14 days





