Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper.executeCommands. The method starts a shell process and writes attacker-controlled command strings directly to the process standard input without sanitization. In affected deployments, this can result in arbitrary operating system command execution.

Project Subscriptions

Vendors Products
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Sun, 17 May 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Oinone
Oinone pamirs
Vendors & Products Oinone
Oinone pamirs

Sat, 16 May 2026 15:45:00 +0000

Type Values Removed Values Added
Title Command Injection Enables Arbitrary OS Execution in Oinone Pamirs 7.0.0

Fri, 15 May 2026 19:45:00 +0000

Type Values Removed Values Added
Title Command Injection Enables Arbitrary OS Execution in Oinone Pamirs 7.0.0

Fri, 15 May 2026 18:15:00 +0000

Type Values Removed Values Added
Title Command Injection in Oinone Pamirs Allowing Arbitrary OS Command Execution
Weaknesses CWE-78

Fri, 15 May 2026 16:45:00 +0000

Type Values Removed Values Added
Title Command Injection in Oinone Pamirs Allowing Arbitrary OS Command Execution
Weaknesses CWE-78

Fri, 15 May 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-77
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 15 May 2026 15:15:00 +0000

Type Values Removed Values Added
Description Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper.executeCommands. The method starts a shell process and writes attacker-controlled command strings directly to the process standard input without sanitization. In affected deployments, this can result in arbitrary operating system command execution.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-15T15:35:24.408Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-39054

cve-icon Vulnrichment

Updated: 2026-05-15T15:35:19.860Z

cve-icon NVD

Status : Deferred

Published: 2026-05-15T15:16:51.753

Modified: 2026-05-18T17:44:03.697

Link: CVE-2026-39054

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-17T19:41:31Z

Weaknesses