Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2026-60121

Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument handling. The endpoint applies escapeshellarg() to the user-supplied host POST parameter before passing it to a system wrapper, but the wrapper retrieves the decoded value from argv and incorporates it into a second shell_exec() call without escaping, allowing injected commands to execute with root privileges via passwordless sudo.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.023
EPSS Ranking 82.1%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-60121
  • Vitec » Flamingo » Version: 4.12.2
    cpe:2.3:a:vitec:flamingo:4.12.2


Contact Us

Shodan ® - All rights reserved