Unrated severityNVD Advisory· Published Sep 28, 2015· Updated May 6, 2026
CVE-2015-5082
CVE-2015-5082
Description
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW_PASSWORD_1 or (2) NEW_PASSWORD_2 parameter to cgi-bin/chpasswd.cgi.
Affected products
1- cpe:2.3:a:endian_firewall:endian_firewall:*:*:*:*:*:*:*:*Range: <=2.5.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- packetstormsecurity.com/files/133469/Endian-Firewall-Proxy-Password-Change-Command-Injection.htmlnvdExploit
- www.exploit-db.com/exploits/37426/nvdExploit
- www.exploit-db.com/exploits/37428/nvdExploit
- www.exploit-db.com/exploits/38096/nvdExploit
- www.rapid7.com/db/modules/exploit/linux/http/efw_chpasswd_execnvd
News mentions
0No linked articles in our index yet.