VYPR

CWE-553

Command Shell in Externally Accessible Directory

VariantIncomplete

Description

A possible shell file exists in /cgi-bin/ or other accessible directories. This is extremely dangerous and can be used by an attacker to execute commands on the web server.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-650

CVEs mapped to this weakness (1)

  • CVE-2025-66620HigJan 7, 2026
    risk 0.52cvss 8.0epss 0.00

    An unused webshell in MicroServer allows unlimited login attempts, with sudo rights on certain files and directories. An attacker with admin access to MicroServer can gain limited shell access, enabling persistence through reverse shells, and the ability to modify or remove data…