CVE-2016-15048

AMTT HiBOS Command Injection RCE via server_ping.php

Basic Information

CVE State
PUBLISHED
Reserved Date
October 21, 2025
Published Date
October 22, 2025
Last Updated
October 22, 2025
Vendor
Anmei Century (Beijing) Technology Co., Ltd.
Product
Hotel Broadband Operation System (HiBOS)
Description
AMTT Hotel Broadband Operation System (HiBOS) contains an unauthenticated command injection vulnerability in the /manager/radius/server_ping.php endpoint. The application constructs a shell command that includes the user-supplied ip parameter and executes it without proper validation or escaping. An attacker can insert shell metacharacters into the ip parameter to inject and execute arbitrary system commands as the web server user. The initial third-party disclosure in 2016 recommended contacting the vendor for remediation guidance. Additionally, this product may have been rebranded under a different name. VulnCheck has observed this vulnerability being exploited in the wild as of 2025-10-14 at 04:45:53.510819 UTC.

CVSS Scores

CVSS v4.0

10.0 - CRITICAL

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

SSVC Information

Exploitation
poc
Automatable
Yes
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (2026-06-01 10:42:45 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CVE 2026-06-01 10:42:45 UTC

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel