Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2012-10039

47
FAUCET Score

CVE-2012-10039 details a critical command injection vulnerability in ZEN Load Balancer versions 2.0 and 3.0-rc1, specifically within the content2-2.cgi script. An authenticated attacker can exploit the unsanitized filelog parameter to inject arbitrary shell commands, leading to remote code execution as the root user. This vulnerability carries a CVSSv4 score of 9.4 (CRITICAL) due to its network-based attack vector, low attack complexity, and complete compromise of confidentiality, integrity, and availability. While the affected versions are unsupported, public exploit code exists, including a Metasploit module, and the vulnerability has garnered significant community discussion, indicating its potential for exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
ZEN Load BalancerZEN Load Balancer
2.0, 3.0-rc1CNA affecteddefault unknown

CVSS Data

CVSS version used by this source: 4.0

9.4CRITICAL

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
HIGH
VS Integrity
HIGH
VS Availability
HIGH
SS Confidentiality
HIGH
SS Integrity
HIGH
SS Availability
HIGH
Exploit Maturity
NOT_DEFINED
CvssVersion
4.0

Exploit Intelligence

EPSS Score
2.39%
Probability of exploitation in next 30 days
EPSS Percentile
82.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Metasploit: ZEN Load Balancer Filelog Command Execution · Sep 14, 2012
This CVE's current EPSS score of 0.0239 is in the 85th percentile among its peer group of 1,124 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

raw.githubusercontent.com / rapid7/metasploit-framework/master/modules/exploits/linux/http/zen_load_balancer_exec.rb
web.archive.org / web/20111015031540/http://www.zenloadbalancer.com
web.archive.org / web/20221203195056/https://itsecuritysolutions.org/2012-09-21-ZEN-Load-Balancer-v2.0-and-v3.0-rc1-multiple-vulnerabilities
exploit-db.com / exploits/21849
fortiguard.com / encyclopedia/ips/33335/zen-load-balancer-filelog-command-execution