S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-17270 Scanner

CVE-2019-17270 scanner - Command Injection vulnerability in Yachtcontrol

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
4.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-17270
9.8
CVSS

Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the "/pages/systemcall.php?command={COMMAND}" page and parameter, where {COMMAND} will be executed and returning the results to the client. Affects Yachtcontrol webservers disclosed via Dutch GPRS/4G mobile IP-ranges. IP addresses vary due to DHCP client leasing of telco's.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Yachtcontrol is a popular navigation and control system used in the boating industry. This innovative product is designed to make life easier for boat owners by providing them with a comprehensive array of features that help them operate their vessel with ease. Yachtcontrol is renowned for its cutting-edge technology, which enables boaters to monitor everything from fuel consumption to weather conditions, and much more.

Recently, a major vulnerability in Yachtcontrol was discovered, which has been designated as CVE-2019-17270. This vulnerability allows unauthenticated users to execute operating system commands via the "/pages/systemcall.php?command={COMMAND}" page and parameter. Essentially, this means that anyone can access and manipulate the system, leading to serious security breaches and data breaches.

If this vulnerability is exploited, it can lead to a wide range of damaging consequences. For example, attackers can gain access to confidential data stored in the system, or even take remote control of the vessel. This puts the boat and its occupants at serious risk, meaning that it is crucial to take appropriate steps to protect against this vulnerability.

In conclusion, it is important to take the necessary precautions to protect against the CVE-2019-17270 vulnerability in Yachtcontrol. Fortunately, thanks to the pro features of the s4e.io platform, anyone can easily and quickly learn about vulnerabilities in their digital assets. By using this platform, you can stay ahead of the curve and ensure that your boat, and your data, remain secure.

 

REFERENCES

Solution Advice

To protect against the CVE-2019-17270 vulnerability in Yachtcontrol, it is important to take the following precautions:

  • Immediately install the latest updates and patches for Yachtcontrol.
  • Use a secure password that is difficult to guess and easy to remember.
  • Be vigilant for any suspicious activity and immediately report it to the relevant authorities.
  • Regularly monitor the performance of the Yachtcontrol system and ensure it is functioning correctly.
  • Consider using additional security measures, such as firewalls and intrusion detection systems.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2019-17270 scanner - Command Injection vulnerability in Yachtcontrol | S4E