VYPR

CloudSetup.cgi

by AVTECH Security Corporation

CVEs (1)

  • CVE-2016-15047HigOct 9, 2025
    risk 0.57cvss epss 0.04

    AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in CloudSetup.cgi is passed to the underlying system command execution without proper validation or whitelisting. An authenticated…