Vulnerability record · CVE-2009-0545 · published 12 February 2009
CVE-2009-0545: ZeroShell kerbynet CGI command injection via type parameter
Zeroshell · Zeroshell
The cgi-bin/kerbynet endpoint in ZeroShell 1.0beta11 and earlier fails to validate the type parameter in a NoAuthREQ x509List action, allowing shell metacharacters to reach a command shell. Because the request requires no authentication, any network-reachable attacker can run arbitrary commands on the appliance.
Description
cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type parameter in a NoAuthREQ x509List action.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityUnauthenticated remote command execution with complete confidentiality, integrity and availability impact, plus public exploit code and a very high EPSS score.
What it is
The cgi-bin/kerbynet endpoint in ZeroShell 1.0beta11 and earlier fails to validate the type parameter in a NoAuthREQ x509List action, allowing shell metacharacters to reach a command shell. Because the request requires no authentication, any network-reachable attacker can run arbitrary commands on the appliance.
Impact
An attacker gains arbitrary command execution with the privileges of the web service, which on a security gateway typically means full control of the device and the traffic it handles.
Attack surface
Reached over the network through the cgi-bin/kerbynet CGI endpoint; the NoAuthREQ action name and the CVSS vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicate no authentication and no user interaction are required.
Exploitation
Not listed in CISA KEV, but EPSS is 0.90386 (99.8th percentile) and public references are tagged Exploit, including an Exploit-DB entry, so working exploit code is publicly available.
What to do
- Apply the vendor patch referenced in the ZeroShell announcements and patch-details pages, or upgrade past 1.0beta11.
- Restrict network access to the ZeroShell web/CGI interface to trusted management networks only.
- Disable or block the cgi-bin/kerbynet endpoint if it is not required.
- Audit the appliance for unauthorized changes and rotate any credentials or keys stored on it.
- Monitor vendor advisories for further updates to this legacy release.
Detection
- Inspect web logs for requests to cgi-bin/kerbynet containing shell metacharacters such as ;, |, `, $() or && in the type parameter.
- Alert on unexpected child processes spawned by the web server or CGI handler on the ZeroShell host.
- Review outbound connections and new listening services on the appliance for signs of post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-0545 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-0545), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.