CVE-2026-105134 PUBLISHED

Ahsay AhsayCBS Replication Receiver UpdateReceivers.do os command injection

Assigner: VulDB
Reserved: 03.10.2026 Published: 04.10.2026 Updated: 05.10.2026

A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve this issue. Upgrading the affected component is advised.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P
CVSS Score: 10

Product Status

Vendor Ahsay
Product AhsayCBS
Versions
  • Version 10.3.0 is affected
  • Version 10.3.1 is affected
  • Version 10.3.2 is affected
  • Version 10.3.4 is unaffected

Credits

  • nickc (VulDB User) reporter
  • VulDB Vulnerability Moderation Team coordinator

References

Problem Types

  • OS Command Injection CWE
  • Command Injection CWE