Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vulnerability in the Managed Ethernet Switch, resulting in full system compromise.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://certvde.com/de/advisories/VDE-2026-038 |
|
History
Tue, 16 Jun 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker can exploit a command injection vulnerability in the Managed Ethernet Switch, resulting in full system compromise. | |
| Title | Command Injection via name parameter | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: CERTVDE
Published:
Updated: 2026-06-16T08:18:02.856Z
Reserved: 2026-04-02T10:13:27.443Z
Link: CVE-2026-5416
No data.
Status : Received
Published: 2026-06-16T10:16:28.857
Modified: 2026-06-16T10:16:28.857
Link: CVE-2026-5416
No data.
OpenCVE Enrichment
No data.