1 results (0.000 seconds)

CVSS: 9.0EPSS: 0%CPEs: 1EXPL: 1

19 Dec 2025 — BrainyCP 1.0 contains an authenticated remote code execution vulnerability that allows logged-in users to inject arbitrary commands through the crontab configuration interface. Attackers can exploit the crontab endpoint by adding a malicious command that spawns a reverse shell to a specified IP and port. • https://brainycp.io • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •