VYPR
Critical severity9.8NVD Advisory· Published Dec 10, 2019· Updated Jun 17, 2026

CVE-2019-17270

CVE-2019-17270

Description

Yachtcontrol through 2019-10-06: It's possible to perform direct Operating System commands as an unauthenticated user via the "/pages/systemcall.php?command={COMMAND}" page and parameter, where {COMMAND} will be executed and returning the results to the client. Affects Yachtcontrol webservers disclosed via Dutch GPRS/4G mobile IP-ranges. IP addresses vary due to DHCP client leasing of telco's.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Yachtcontrol/Yachtcontrolllm-create2 versions
    <=2019-10-06+ 1 more
    • (no CPE)range: <=2019-10-06
    • cpe:2.3:a:yachtcontrol:yachtcontrol:*:*:*:*:*:*:*:*range: <=2019-10-06
  • Yachtcontrol/Yachtcontroldescription

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.