Command Injection Vulnerability in Affected System Configuration by Vendor ABC
CVE-2026-7849

9.3CRITICAL

Key Information:

Vendor
CVE Published:
30 July 2026

What is CVE-2026-7849?

An improper neutralization of special elements allows an unauthenticated remote attacker to inject commands into the system configuration of ABC Application. Once injected, these commands can be executed with root privileges, potentially leading to system compromise and unauthorized access to sensitive data.

Affected Version(s)

CHARX SEC-3000 1.0.0 < 1.9.1

CHARX SEC-3050 1.0.0 < 1.9.1

CHARX SEC-3100 1.0.0 < 1.9.1

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ZDI
.