VYPR
High severity8.8NVD Advisory· Published Feb 9, 2021· Updated Jun 17, 2026

CVE-2021-26551

CVE-2021-26551

Description

An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection mechanism, by creating /config/ConsoleModuleUnlock.txt and editing /config/admin/admintool.xml to enable the Console module.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • SmartFoxServer/SmartFoxServerdescription
  • cpe:2.3:a:smartfoxserver:smartfoxserver:2.17.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:smartfoxserver:smartfoxserver:2.17.0:*:*:*:*:*:*:*
    • (no CPE)range: =2.17.0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.