HIGH 7.2 NVD
CVE-2026-27564
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin creden
A high-privileged remote attacker can exploit a command injection vulnerability in the /api/datastorage/data endpoint by sending a PUT request with admin credentials allowing execution of commands with root privileges on the device.
References
- https://www.certvde.com/en/advisories/VDE-2026-014/
- https://www.certvde.com/en/advisories/VDE-2026-027/
- https://www.certvde.com/en/advisories/VDE-2026-028/
This high severity vulnerability with a CVSS score of 7.2 was published on 2026-09-16 via NVD.
vulnfeed aggregates 14123 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.