CVE-2017-7175

critical
Published 2017-07-10 · Modified 2026-05-13
CVSS v3
9.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS v2
9.0
VIR risk
9.9

Description

NfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt parameter (aka the "Custom output format" field).

Predictions

Exploit likelihood
98%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://sourceforge.net/p/nfsen/news/2017/01/nfsen-138-released---security-fix/

Application impact

VendorProductVersionsFixed
nfsennfsen{"endIncluding":"1.3.7"}

References

CWEs

CWE-78

Verify integrity in audit chain (admin only). AS-IS.