← Vulnerability feed

Vulnerability record · CVE-2006-5792 · published 7 November 2006

CVE-2006-5792: XLink Omni-NFS Enterprise unspecified remote code execution

Xlink Technology · Omni Nfs X Enterprise

XLink Omni-NFS Enterprise contains an unspecified vulnerability that allows remote attackers to execute arbitrary code. The disclosure provides no technical detail about the flaw itself, only a reference to a remote exploit module (vd_xlink2.pm), so the exact vulnerable component and mechanism are unknown. It matters because a network-reachable code execution flaw in an NFS server product can give an unauthenticated attacker full control of the host.

7.5 CVSS 2.0 High EPSS 61% · top 0.9%
7.5CVSS 2.0 base score
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Unspecified vulnerability in XLink Omni-NFS Enterprise allows remote attackers to execute arbitrary code via unspecified vectors, as demonstrated by vd_xlink2.pm, an "Omni-NFS Enterprise remote exploit." NOTE: this is probably a different vulnerability than CVE-2006-5780. As of 20061107, this disclosure has no actionable information. However, since it is from a reliable researcher, it is being assigned a CVE identifier for tracking purposes.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: low.

high priorityNetwork-reachable, unauthenticated code execution with a public exploit reference and very high EPSS, though technical details and patch status are unconfirmed.

What it is

XLink Omni-NFS Enterprise contains an unspecified vulnerability that allows remote attackers to execute arbitrary code. The disclosure provides no technical detail about the flaw itself, only a reference to a remote exploit module (vd_xlink2.pm), so the exact vulnerable component and mechanism are unknown. It matters because a network-reachable code execution flaw in an NFS server product can give an unauthenticated attacker full control of the host.

Impact

An attacker can execute arbitrary code on the affected system, likely with the privileges of the Omni-NFS service. That yields host compromise and potential access to any data or network shares the server exposes.

Attack surface

The CVSS vector AV:N/AC:L/Au:N indicates the flaw is reachable over the network with no authentication and no user interaction. The description does not identify which service, port or protocol path is involved, so the precise entry point cannot be confirmed from this record.

Exploitation

No CISA KEV listing and no ransomware association are recorded, but the references include an exploit-tagged link to a public exploit module, and EPSS is high at roughly 0.60 (99th percentile), indicating elevated likelihood of exploitation activity.

What to do

  • Apply the vendor patch or fixed Omni-NFS Enterprise release if one is available; the record does not name affected or fixed versions, so confirm with XLink support.
  • If no patch exists, restrict network access to the Omni-NFS service to trusted hosts only and block it at the perimeter.
  • Run the service with least privilege and isolate the host on a segmented network away from sensitive data.
  • Monitor vendor and CVE channels for updated technical details, since the original disclosure had no actionable information.

Detection

  • Monitor for unexpected child processes or command shells spawned by the Omni-NFS service process.
  • Alert on inbound connections to Omni-NFS ports from untrusted or unusual source addresses.
  • Review host and NFS logs for anomalous file operations, new files, or service restarts around suspicious connections.
  • Hunt for known exploit artifacts or module names such as vd_xlink2.pm in tooling or process telemetry.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-5792 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2006-5792), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.