CVE-2026-101947None▾ SunlitExifTool for photo and video 5.0.1-gms by CellHubs constructs shell command strings from file paths and invokes /system/bin/sh -c. In the CSV-export path, the selected media path is merely surrounded with single quotes; embedded single q…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
ExifTool for photo and video 5.0.1-gms by CellHubs constructs shell command strings from file paths and invokes /system/bin/sh -c. In the CSV-export path, the selected media path is merely surrounded with single quotes; embedded single quotes are not escaped.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2022-37902High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37899High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37900High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37901High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37898High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface
CVE-2022-37912High· 7.2Authenticated command injection vulnerabilities exist in the ArubaOS command line interface