S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jul 16, 2025

CVE-2020-29390 Scanner

CVE-2020-29390 Scanner - Command Injection vulnerability in Zeroshell

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3k
Times Used
continuous scan runs
4.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-29390
9.8
CVSS

Zeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated attacker to execute a system command by using shell metacharacters and the %0a character.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Zeroshell is a Linux-based distribution for servers and embedded devices, particularly designed for network management tasks. It is primarily used by IT administrators and network specialists to manage and secure network connectivity and access. Users deploy Zeroshell to handle services such as routing, bridging, firewalling, and VPN configurations. The software is known for its flexibility and ease of deployment in various network environments, including educational institutions, small to medium-sized enterprises, and remote offices. Its web-based interface allows an easy and efficient setup, making it accessible even for individuals with limited technical expertise.

The Command Injection vulnerability in Zeroshell allows remote attackers to inject and execute arbitrary commands on the host operating system. The vulnerability is found in the parameter StartSessionSubmit of the CGI script /cgi-bin/kerbynet. An unauthenticated attacker can exploit this by manipulating the server input through specially crafted HTTP requests. The issue arises due to insufficient validation of input parameters, where shell metacharacters are not adequately sanitized. This makes the system vulnerable to crafting inputs that lead to arbitrary command execution.

Technical details of the vulnerability reveal that it is triggered via the StartSessionSubmit parameter in HTTP requests. Attackers can utilize shell metacharacters concatenated with the %0a character to manipulate processed input. The vulnerability resides in the insufficient input validation on the server-side, allowing attackers to execute commands remotely. Attack vectors include manipulating the input to include operating system commands, potentially leading to escalated privileges. The parameter exploitation involves injecting a command payload within the input string, which bypasses regular authentication safeguards.

When exploited, this vulnerability can have severe impacts on a compromised system. Attackers may execute arbitrary commands with potentially elevated privileges, leading to unauthorized data access and system integrity loss. It can enable further exploitation, such as downloading malware, continuing network attacks, or disrupting network services. As a result, organizations could face operational disruptions, loss of sensitive data, and reputational damage. Additionally, this exposure increases the risk of attack vectors used in broader campaigns targeting critical network infrastructure.

REFERENCES

Solution Advice
  • Upgrade Zeroshell to a version where this vulnerability is fixed.
  • Implement input validation and sanitization mechanisms to prevent command injection vectors.
  • Deploy web application firewalls to monitor and filter malicious traffics capable of command injection.
  • Regularly apply all security updates and patches provided by the vendor.
  • Restrict unnecessary network exposure of management interfaces to trusted networks only.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.