CVE-2025-34103
An unauthenticated command injection vulnerability exists in WePresent WiPG-1000 firmware versions prior to 2.2.3.0, due to improper input handling in the undocumented /cgi-bin/rdfs.cgi endpoint. The Client parameter is not sanitized before being passed to a system call, allowing an unauthenticated remote attacker to execute arbitrary commands as the web server user.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 6.04%
- CWE
- CWE-78, CWE-306
- Published
- 2025-07-15
- Last modified
- 2026-05-15
Affected products
- WePresent (Barco) WiPG-1000
- WePresent (Barco) WiPG-1000
Weakness type
Related vulnerabilities
- CVE-2026-79689 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-79641 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-87088 — Tanium addressed an unauthorized code execution vulnerability in Enforce.
- CVE-2026-78630 — Improper Input Neutralization in Okta Access Gateway SNMP Configuration Processing
- CVE-2026-82004 — Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') (CWE-78)
- CVE-2026-81349 — Azure HDInsight Ambari Elevation of Privilege Vulnerability
- CVE-2026-86733 — Snipe-IT before 8.7.0 Remote Code Execution via Backup Restore
- CVE-2026-61517 — Netis NX10 OS Command Injection via Ping Diagnostic Handler