CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary OS commands through the local service interface, resulting in command execution on the victim's local computer.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
Update Linux's NHIServisign version 1.0.26.0625 or later.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary OS commands through the local service interface, resulting in command execution on the victim's local computer. | |
| Title | Changing|CGServiSign - OS Command Injection | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2026-09-23T08:18:49.332Z
Reserved: 2026-07-08T01:35:23.369Z
Link: CVE-2026-15027
No data.
Status : Received
Published: 2026-09-23T09:17:07.657
Modified: 2026-09-23T09:17:07.657
Link: CVE-2026-15027
No data.
OpenCVE Enrichment
No data.
Weaknesses