← Terug naar overzicht

CVE-2026-78211 affects 4MOSAn GCB Doctor, a product developed by 4MOSAn Security Technology. The vulnerability is an OS Command Injection flaw that can be exploited by unauthenticated remote attackers. Attackers can inject malicious commands through an unremoved ADOdb test page parameter left in the application. Successful exploitation allows arbitrary system command execution on the affected server. No authentication is required, making this vulnerability particularly dangerous and easily exploitable. The vulnerability was reported via Taiwan's TWCERT/CC advisory system. The issue stems from improper removal of a database library test page exposed in the production environment. This type of leftover debug/test functionality represents a significant security risk. The criticality is rated High due to the unauthenticated remote code execution potential.

Affected products

  • 4MOSAn GCB Doctor

Related CVE's

  • CVE-2026-78211

Categories

  • Enterprise Applications
  • Web Technologies