Vulnerability record · CVE-2017-14535 · published 16 February 2018
CVE-2017-14535: trixbox lang parameter OS command injection
Netfortris · Trixbox
trixbox 2.8.0.4 passes the lang parameter to /maint/modules/home/index.php without sanitizing shell metacharacters, allowing OS command injection. An authenticated attacker can execute arbitrary commands on the underlying host, which matters because trixbox is a PBX appliance often holding call and credential data.
Description
trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote command injection with public exploit code and very high EPSS, though it requires authentication and affects an end-of-life product.
What it is
trixbox 2.8.0.4 passes the lang parameter to /maint/modules/home/index.php without sanitizing shell metacharacters, allowing OS command injection. An authenticated attacker can execute arbitrary commands on the underlying host, which matters because trixbox is a PBX appliance often holding call and credential data.
Impact
An attacker with a valid low-privileged account gains remote command execution as the web server user, leading to full compromise of the PBX host and any data or telephony credentials it holds.
Attack surface
Reached over the network via HTTP requests to /maint/modules/home/index.php with a crafted lang parameter. The CVSS vector shows PR:L, so some authentication is required; no user interaction is needed.
Exploitation
Public exploit code is referenced in multiple advisories and Packet Storm, and EPSS is 0.50069 (98.8th percentile), indicating elevated likelihood of exploitation. The CVE is not listed in CISA KEV, so no confirmed in-the-wild use is documented here.
What to do
- Apply the vendor fix or upgrade trixbox past 2.8.0.4; if no patch exists, isolate or retire the appliance.
- Restrict network access to the /maint/ administrative interface to trusted management hosts only.
- Enforce strong unique credentials and remove or disable unused accounts to limit the PR:L foothold.
- Deploy WAF or input filtering that blocks shell metacharacters in the lang parameter as a stopgap.
- Monitor the host for unexpected child processes spawned by the web server.
Detection
- Alert on HTTP requests to /maint/modules/home/index.php with shell metacharacters (;, |, &, $, backticks) in the lang parameter.
- Monitor web server process trees for shell or command interpreters spawned by the web user.
- Review trixbox host logs for anomalous outbound connections or new files following maint interface access.
- Baseline and alert on unusual command execution by the web service account.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2017-14535 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-14535), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.