← Vulnerability feed

Vulnerability record · CVE-2009-0545 · published 12 February 2009

CVE-2009-0545: ZeroShell kerbynet CGI command injection via type parameter

Zeroshell · Zeroshell

The cgi-bin/kerbynet endpoint in ZeroShell 1.0beta11 and earlier fails to validate the type parameter in a NoAuthREQ x509List action, allowing shell metacharacters to reach a command shell. Because the request requires no authentication, any network-reachable attacker can run arbitrary commands on the appliance.

10.0 CVSS 2.0 High EPSS 90% · top 0.2% CWE-20 · Improper input validation
10.0CVSS 2.0 base score
90%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

cgi-bin/kerbynet in ZeroShell 1.0beta11 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the type parameter in a NoAuthREQ x509List action.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityUnauthenticated remote command execution with complete confidentiality, integrity and availability impact, plus public exploit code and a very high EPSS score.

What it is

The cgi-bin/kerbynet endpoint in ZeroShell 1.0beta11 and earlier fails to validate the type parameter in a NoAuthREQ x509List action, allowing shell metacharacters to reach a command shell. Because the request requires no authentication, any network-reachable attacker can run arbitrary commands on the appliance.

Impact

An attacker gains arbitrary command execution with the privileges of the web service, which on a security gateway typically means full control of the device and the traffic it handles.

Attack surface

Reached over the network through the cgi-bin/kerbynet CGI endpoint; the NoAuthREQ action name and the CVSS vector AV:N/AC:L/Au:N/C:C/I:C/A:C indicate no authentication and no user interaction are required.

Exploitation

Not listed in CISA KEV, but EPSS is 0.90386 (99.8th percentile) and public references are tagged Exploit, including an Exploit-DB entry, so working exploit code is publicly available.

What to do

  • Apply the vendor patch referenced in the ZeroShell announcements and patch-details pages, or upgrade past 1.0beta11.
  • Restrict network access to the ZeroShell web/CGI interface to trusted management networks only.
  • Disable or block the cgi-bin/kerbynet endpoint if it is not required.
  • Audit the appliance for unauthorized changes and rotate any credentials or keys stored on it.
  • Monitor vendor advisories for further updates to this legacy release.

Detection

  • Inspect web logs for requests to cgi-bin/kerbynet containing shell metacharacters such as ;, |, `, $() or && in the type parameter.
  • Alert on unexpected child processes spawned by the web server or CGI handler on the ZeroShell host.
  • Review outbound connections and new listening services on the appliance for signs of post-exploitation activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-0545 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2020-29390Zeroshell os command injection vulnerabilityZeroshell 3.9.3 contains a command injection vulnerability in the /cgi-bin/kerbynet StartSessionSubmit parameter that could allow an unauthenticated …EPSS 40%9.8CVE-2019-12725Zeroshell web interface OS command injection allows unauthenticated RCEZeroshell 3.9.0 mishandles several HTTP parameters in its web application, allowing OS commands to be injected into them. Because the flaw is reachab…EPSS 90%analysed8.8CVE-2021-41738Zeroshell os command injection vulnerabilityZeroShell 3.9.5 has a command injection vulnerability in /cgi-bin/kerbynet IP parameter, which may allow an authenticated attacker to execute system …EPSS 1.8%9.5CVE-2026-88771Citrix NetScaler Improper Input Validation VulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEV9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 0.90%8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed9.3CVE-2026-12569PTC Windchill PDMlink and FlexPLM deserialization RCEPTC Windchill PDMlink and FlexPLM contain a deserialization of untrusted data flaw (also classified as improper input validation) that allows remote …KEVEPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2009-0545), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.