<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Os-Command-Injection — PoC Archive</title><link>https://poc.intelseclab.com/tags/os-command-injection/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 11 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/os-command-injection/index.xml" rel="self" type="application/rss+xml"/><item><title>Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Windows WMI Config Wizard (CVE-2021-25296)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25296-nagios-xi-windowswmi-command-injection/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25296-nagios-xi-windowswmi-command-injection/</guid><description>High severity (CVSS 8.8) — web · CVE-2021-25296. Status: Weaponized (public Metasploit module + nuclei templates, in CISA KEV). Affects: Nagios XI — Windows WMI monitoring configuration wizard. Tags: nagios-xi, os-command-injection, authenticated, config-wizard, windowswmi, cwe-78, kev, metasploit.</description><category>web</category><category>High</category><category>nagios-xi</category><category>os-command-injection</category><category>authenticated</category><category>config-wizard</category><category>windowswmi</category><category>cwe-78</category><category>kev</category><category>metasploit</category></item><item><title>Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Switch Config Wizard (CVE-2021-25297)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25297-nagios-xi-switch-command-injection/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25297-nagios-xi-switch-command-injection/</guid><description>High severity (CVSS 8.8) — web · CVE-2021-25297. Status: Weaponized (public Metasploit module + nuclei templates, in CISA KEV). Affects: Nagios XI — Switch (SNMP) monitoring configuration wizard. Tags: nagios-xi, os-command-injection, authenticated, config-wizard, switch, cwe-78, kev, metasploit.</description><category>web</category><category>High</category><category>nagios-xi</category><category>os-command-injection</category><category>authenticated</category><category>config-wizard</category><category>switch</category><category>cwe-78</category><category>kev</category><category>metasploit</category></item><item><title>Nagios XI 5.5.6–5.7.5 Authenticated OS Command Injection — Cloud-VM Config Wizard (CVE-2021-25298)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25298-nagios-xi-cloudvm-command-injection/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2021-25298-nagios-xi-cloudvm-command-injection/</guid><description>High severity (CVSS 8.8) — web · CVE-2021-25298. Status: Weaponized (public Metasploit module + nuclei templates, in CISA KEV). Affects: Nagios XI — Cloud/VM monitoring configuration wizard (DigitalOcean provider sub-option). Tags: nagios-xi, os-command-injection, authenticated, config-wizard, cloud-vm, cwe-78, kev, metasploit.</description><category>web</category><category>High</category><category>nagios-xi</category><category>os-command-injection</category><category>authenticated</category><category>config-wizard</category><category>cloud-vm</category><category>cwe-78</category><category>kev</category><category>metasploit</category></item><item><title>D-Link AX1500 SetDeviceSettings `DeviceName` OS Command Injection (CVE-2025-60854)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-60854-dlink-ax1500-devicename-command-injection/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-60854-dlink-ax1500-devicename-command-injection/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-60854. Status: Weaponized. Affects: D-Link AX1500 router firmware (HNAP/DHMAPI web management SOAP interface). Tags: d-link, ax1500, router, command-injection, os-command-injection, hnap, soap, telnetd, cwe-78, iot.</description><category>network</category><category>Critical</category><category>d-link</category><category>ax1500</category><category>router</category><category>command-injection</category><category>os-command-injection</category><category>hnap</category><category>soap</category><category>telnetd</category><category>cwe-78</category><category>iot</category></item><item><title>FortiSandbox 4.4.0-4.4.8 — OS Command Injection via tracer-behavior Endpoint (CVE-2026-39808)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-39808-fortisandbox-os-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-39808-fortisandbox-os-command-injection/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-39808. Status: Weaponized — real, working exploit verified from two independent sources. Affects: Fortinet FortiSandbox. Tags: fortinet, fortisandbox, os-command-injection, unauthenticated, root-rce, cwe-78, actively-exploited, kev.</description><category>network</category><category>Critical</category><category>fortinet</category><category>fortisandbox</category><category>os-command-injection</category><category>unauthenticated</category><category>root-rce</category><category>cwe-78</category><category>actively-exploited</category><category>kev</category></item><item><title>Dolibarr ERP/CRM OS Command Injection via MAIN_ODT_AS_PDF (CVE-2026-23500)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23500-dolibarr-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-23500-dolibarr-command-injection/</guid><description>Critical severity — web · CVE-2026-23500 / GHSA-w5j3-8fcr-h87w. Status: PoC. Affects: Dolibarr ERP/CRM. Tags: dolibarr, os-command-injection, rce, authenticated, php, odt-to-pdf, reverse-shell, erp.</description><category>web</category><category>Critical</category><category>dolibarr</category><category>os-command-injection</category><category>rce</category><category>authenticated</category><category>php</category><category>odt-to-pdf</category><category>reverse-shell</category><category>erp</category></item><item><title>Ivanti Sentry Pre-Auth RCE + Auth Bypass (CVE-2026-10520 / CVE-2026-10523)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-10520-ivanti-sentry-rce/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-10520-ivanti-sentry-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-10520, CVE-2026-10523. Status: PoC. Affects: Ivanti Sentry (formerly MobileIron Sentry). Tags: pre-auth, RCE, OS-command-injection, Ivanti, Sentry, MICS-API, auth-bypass, admin-creation, CISA-KEV.</description><category>network</category><category>Critical</category><category>pre-auth</category><category>RCE</category><category>OS-command-injection</category><category>Ivanti</category><category>Sentry</category><category>MICS-API</category><category>auth-bypass</category><category>admin-creation</category><category>CISA-KEV</category></item></channel></rss>