CVE-2024-51378 is a critical authentication bypass and command injection vulnerability affecting CyberPanel versions through 2.3.6 and 2.3.7. It allows remote, unauthenticated attackers to execute arbitrary commands by exploiting improper handling of POST requests and shell metacharacters in the statusfile property of /dns/getresetstatus or /ftp/getresetstatus. With a CVSS score of 9.8 (Critical) and a FAUCET Risk Score of 100/100, this vulnerability poses a severe risk, enabling complete compromise of affected systems. It is actively exploited in the wild, including in ransomware campaigns by groups like PSAUX, and has readily available exploit modules in Metasploit and Nuclei, along with significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.3.8CPE matchmatch criteria | cpe:2.3:a:cyberpanel:cyberpanel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.