VYPR
Medium severity6.5NVD Advisory· Published Aug 26, 2025· Updated Jun 17, 2026

CVE-2025-50974

CVE-2025-50974

Description

The Calamaris log exporter CGI (/cgi-bin/logs.cgi/calamaris.dat) in IPFire 2.29 does not properly sanitize user-supplied input before incorporating parameter values into a shell command. An unauthenticated remote attacker can inject arbitrary OS commands by embedding shell metacharacters in any of the following parameters BYTE_UNIT, DAY_BEGIN, DAY_END, HIST_LEVEL, MONTH_BEGIN, MONTH_END, NUM_CONTENT, NUM_DOMAINS, NUM_HOSTS, NUM_URLS, PERF_INTERVAL, YEAR_BEGIN, YEAR_END.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Ipfire/Ipfire3 versions
    cpe:2.3:a:ipfire:ipfire:2.29:-:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:ipfire:ipfire:2.29:-:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 2.29

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.