Panabit iXCache Remote Code Execution Scanner

Targets the date_config endpoint with crafted input to execute arbitrary system commands, achieving full remote control of the caching server.

Short Info


Level

Critical

Single Scan

Single Scan

Can be used by

Asset Owner

Estimated Time

1 minute

Time Interval

4 weeks 17 hours

Scan only one

Domain, IPv4, Subdomain

Toolbox

Panabit iXCache is a high-performance caching solution deployed by ISPs and large enterprises to accelerate content delivery and reduce bandwidth costs. It sits inline with network traffic, caching frequently accessed data to improve user experience. Network administrators rely on its modular architecture for granular traffic management and optimization.

The Remote Code Execution vulnerability arises from insufficient input sanitization in the date_config module. Attackers can inject malicious commands through unvalidated parameters, which the system then executes with elevated privileges. This flaw stems from insecure handling of user-supplied data in shell command construction.

Specifically, the vulnerability is triggered via the date_config.php endpoint, where the 'date' parameter is passed unsanitized to a system() call. An attacker can send a crafted HTTP request containing command separators like semicolons or pipes to execute arbitrary OS commands on the iXCache server.

Successful exploitation allows an attacker to gain complete control over the iXCache appliance, potentially leading to data exfiltration, network pivoting, or service disruption. Given its position in critical network infrastructure, this RCE flaw poses a severe risk to organizational security and data integrity.

Get started to protecting your digital assets