S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2019-12725 Scanner

CVE-2019-12725 scanner - Remote Code Execution (RCE) vulnerability in Zeroshell

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.1k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-12725
9.8
CVSS

Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Zeroshell is a Linux-based open-source software that provides network services including firewall, routing, VPN, and captive portal solutions. It is designed to be used in small to medium-sized networks as a router and server. Its main purpose is to simplify network administration and security by providing an all-in-one solution for network services. The software is often used in schools, universities, and small businesses where a dedicated IT staff is not present.

The CVE-2019-12725 vulnerability in Zeroshell is a remote code execution vulnerability that allows unauthenticated attackers to inject OS commands through the mishandling of a few HTTP parameters. This type of vulnerability occurs when an attacker exploits a flaw in the system that allows them to execute arbitrary code or commands. In this case, an attacker can send a specially crafted request to the Zeroshell web application, which will then execute the injected command as if it were a legitimate command.

When this vulnerability is exploited, an attacker can gain complete control of the entire network that Zeroshell is running on. This means that they can steal sensitive information, install malware, and cause significant damage to the network. The severity of this vulnerability cannot be understated given the critical functions that Zeroshell provides.

With the pro features of the s4e.io platform, users can easily and quickly learn about vulnerabilities in their digital assets. By using this platform, you can take proactive steps to protect your network from potential attacks like the CVE-2019-12725 vulnerability in Zeroshell. With a comprehensive understanding of your network's weaknesses and vulnerabilities, you can take the necessary steps to protect it from threats that can cause serious damage to your organization.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Ensure that Zeroshell is updated to the latest version, which contains a fix for this vulnerability.
  • Tighten security by restricting access to the web interface to only trusted sources.
  • Implement strict input validation to prevent attacks that exploit HTTP parameters.
  • Disable unnecessary services and ports to reduce the attack surface.
  • Consider using additional security tools such as firewalls and intrusion detection systems.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.