CVE-2026-12104 PUBLISHED

Authenticated OS Command Injection in Bondix

Assigner: NCSC.ch
Reserved: 12.06.2026 Published: 19.06.2026 Updated: 19.06.2026

OS command injection in the environment and tunnel configuration functionality in SIMA GmbH Bondix through version 1.25.7.5 on Linux allows an authenticated attacker with configuration write access to execute arbitrary operating-system commands via crafted configuration values passed to server-side scripts.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/AU:Y/R:U/RE:L/U:Amber
CVSS Score: 8.6

Product Status

Vendor SIMA GmbH
Product Bondix Server
Versions Default: unaffected
  • affected from 0 to 1.25.7.5 (incl.)
  • Version 1.25.7.6 is unaffected

References

Problem Types

  • CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection') CWE

Impacts

  • CAPEC-88 OS Command Injection