cvedb.io
CVE-2025-50974
MEDIUM · CVSS 6.5
EPSS exploitation probability: 0%
Published 2025-08-26T17:15:38.490 · Last modified 2026-06-17T09:35:28.243

Summary

The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorporating parameter values into a shell command. An unauthenticated remote attacker can inject arbitrary OS commands by embedding shell metacharacters in any of the following parameters BYTE_UNIT, DAY_BEGIN, DAY_END, HIST_LEVEL, MONTH_BEGIN, MONTH_END, NUM_CONTENT, NUM_DOMAINS, NUM_HOSTS, NUM_URLS, PERF_INTERVAL, YEAR_BEGIN, YEAR_END.

Affected products

ipfire — ipfire

Does this affect you?

Add your gear to cvedb and we'll alert you only when ipfire ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.