go to Center block
Upper block

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Changing|CGServiSign - OS Command Injection

TVN ID TVN-202609009
CVE ID CVE-2026-15027
CVSS 8.6 (High) CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
8.8 (High) CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products NHIServisign for Linux version 1.0.23.1227
Description CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary OS commands through the local service interface, resulting in command execution on the victim's local computer.
Solution Update Linux's NHIServisign version 1.0.26.0625 or later.
Credit mlgzackfly
Public Date 2026-09-23
Top