CVE-2026-83549High· 7.8▾ Abyssal⚠ Exploited in the wild0dayPoC availablePost-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potenti…
▾ Abyssal zone — Critical with a public exploit or in-the-wild use
impact 42.9 · likelihood 1.7 · exploitation 25
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Federal remediation due Sep 5, 2026
Last analysed / modified upstream
8.5%
Metasploit ×1 (last check)
Added to the CISA catalog on Sep 2, 2026. Federal remediation due Sep 5, 2026. View catalog ↗
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.
sma8200v < 12.4.3-03526sma8200v >= 12.5.0, < 12.5.0-02952sma6210_firmware < 12.4.3-03526sma6210_firmware >= 12.5.0, < 12.5.0-02952sma7210_firmware < 12.4.3-03526sma7210_firmware >= 12.5.0, < 12.5.0-02952Upgrade past the affected range:
sma8200v 12.5.0-02952sma6210_firmware 12.5.0-02952sma7210_firmware 12.5.0-02952Connected by shared product, vendor, weakness, or advisory.
CVE-2018-11138Critical· 9.8The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
CVE-2024-51378Critical· 10.0getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing se…
CVE-2025-23006Critical· 9.8Pre-authentication deserialization of untrusted data vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), which in specific conditions could potentially enable a remote…
CVE-2024-9474High· 7.2A privilege escalation vulnerability in Palo Alto Networks PAN-OS software allows a PAN-OS administrator with access to the management web interface to perform actions on the firewall with root privileges. Cloud NGFW and Prisma Access a…
CVE-2019-15107Critical· 9.8An issue was discovered in Webmin <=1.920
CVE-2017-6884High· 8.8A command injection vulnerability was discovered on the Zyxel EMG2926 home router with firmware V1.00(AAQT.4)b8