Operating System Command Injection Vulnerability in UpSnap Web App
CVE-2026-49481
9.6CRITICAL
What is CVE-2026-49481?
The UpSnap web application, designed for wake on lan functionality, contains an OS command injection vulnerability in its device management feature. This issue arises from improper handling of user-controlled input within shell command templates. Specifically, malicious inputs can be injected into the wake_cmd and shutdown_cmd parameters, leading to arbitrary command execution on the server. This vulnerability impacts all versions before 5.4.0, allowing low-privileged users with permissions to create or edit devices to exploit the flaw. The issue has been addressed in version 5.4.0, which users are urged to upgrade to in order to mitigate potential security risks.
Affected Version(s)
UpSnap < 5.4.0
