CVE-2012-10028 is a critical vulnerability in Netwin SurgeFTP versions 23c8 and prior, allowing authenticated users to execute arbitrary system commands through crafted POST requests to the surgeftpmgr.cgi web interface. This high-severity flaw (CVSS 8.6) enables full remote code execution on the underlying system, requiring high privileges but no user interaction. While not on the KEV catalog, a Metasploit module exists, and the vulnerability has significant community discussion, indicating potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 23c8CPE match | cpe:2.3:a:netwin:surgeftp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.