{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-27551/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-27551"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","remote-code-execution","command-injection","cve-2026-27551"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eCVE-2026-27551 is a command injection vulnerability discovered in the /index.php/ajax/parameterManage endpoint of an affected web-based management interface. The vulnerability allows a remote attacker who possesses low-privileged user credentials to bypass intended security controls and execute arbitrary system commands with root-level privileges on the underlying device. This flaw presents a significant security risk, as it effectively enables full device compromise once initial access has been achieved via the required user account. The vulnerability has been assigned a CVSS v3.1 base score of 8.8, reflecting its high impact and the relative ease of exploitation for an authenticated user. Organizations utilizing devices with this vulnerable AJAX endpoint should prioritize implementing vendor-supplied patches or restricting access to the management interface.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full remote code execution with root privileges on the affected hardware. This allows attackers to install persistent backdoors, exfiltrate sensitive configuration data, or leverage the device as a pivot point for further lateral movement within the network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize patching all internet-facing management interfaces that utilize the /index.php/ajax/parameterManage endpoint. Monitor web server access logs for anomalous POST requests directed at this specific URI, particularly those containing shell metacharacters or encoded commands.\u003c/p\u003e\n","date_modified":"2026-09-16T09:48:49Z","date_published":"2026-09-16T09:48:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-27551/","summary":"A low-privileged remote attacker can exploit a command injection vulnerability at the /index.php/ajax/parameterManage endpoint using valid credentials to gain root-level code execution.","title":"Command Injection in /index.php/ajax/parameterManage Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-27551/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-27551","version":"https://jsonfeed.org/version/1.1"}