CVE-2009-0545

High PUBLISHED

cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type...

Vendor: ZeroShell Product: ZeroShell

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
10.0 High EPSS 90.4%

At a Glance

cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type parameter in a NoAuthREQ x509List action.

nuclei_scanner
CVE Published
Feb 12, 2009
Exploitation Reported
Jun 10, 2025
CVSS
10.0 High
EPSS
90.4%
Remote Low complexity Unauthenticated

CVE References

Show 1 more reference