← Vulnerability feed

Vulnerability record · CVE-2017-14535 · published 16 February 2018

CVE-2017-14535: trixbox lang parameter OS command injection

Netfortris · Trixbox

trixbox 2.8.0.4 passes the lang parameter to /maint/modules/home/index.php without sanitizing shell metacharacters, allowing OS command injection. An authenticated attacker can execute arbitrary commands on the underlying host, which matters because trixbox is a PBX appliance often holding call and credential data.

8.8 CVSS 3.1 High EPSS 50% · top 1.1% CWE-78 · OS command injection
8.8CVSS 3.1 base score, v2 9.0
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityRemote command injection with public exploit code and very high EPSS, though it requires authentication and affects an end-of-life product.

What it is

trixbox 2.8.0.4 passes the lang parameter to /maint/modules/home/index.php without sanitizing shell metacharacters, allowing OS command injection. An authenticated attacker can execute arbitrary commands on the underlying host, which matters because trixbox is a PBX appliance often holding call and credential data.

Impact

An attacker with a valid low-privileged account gains remote command execution as the web server user, leading to full compromise of the PBX host and any data or telephony credentials it holds.

Attack surface

Reached over the network via HTTP requests to /maint/modules/home/index.php with a crafted lang parameter. The CVSS vector shows PR:L, so some authentication is required; no user interaction is needed.

Exploitation

Public exploit code is referenced in multiple advisories and Packet Storm, and EPSS is 0.50069 (98.8th percentile), indicating elevated likelihood of exploitation. The CVE is not listed in CISA KEV, so no confirmed in-the-wild use is documented here.

What to do

  • Apply the vendor fix or upgrade trixbox past 2.8.0.4; if no patch exists, isolate or retire the appliance.
  • Restrict network access to the /maint/ administrative interface to trusted management hosts only.
  • Enforce strong unique credentials and remove or disable unused accounts to limit the PR:L foothold.
  • Deploy WAF or input filtering that blocks shell metacharacters in the lang parameter as a stopgap.
  • Monitor the host for unexpected child processes spawned by the web server.

Detection

  • Alert on HTTP requests to /maint/modules/home/index.php with shell metacharacters (;, |, &, $, backticks) in the lang parameter.
  • Monitor web server process trees for shell or command interpreters spawned by the web user.
  • Review trixbox host logs for anomalous outbound connections or new files following maint interface access.
  • Baseline and alert on unusual command execution by the web service account.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-14535 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-7351Trixbox CE endpoint_devicemap.php OS command injectionFonality Trixbox Community Edition contains an OS command injection flaw in endpoint_devicemap.php. An attacker with low-privileged access can run ar…EPSS 65%analysed7.5CVE-2014-5109Netfortris trixbox sql injection vulnerabilitySQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attackers to execute arbitrary SQL co…EPSS 3.4%7.5CVE-2014-5112Netfortris trixbox code injection vulnerabilitymaint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacharacters in the lang parameter.EPSS 9.2%7.5CVE-2010-0702Netfortris trixbox sql injection vulnerabilitySQL injection vulnerability in cisco/services/PhonecDirectory.php in Fonality Trixbox 2.2.4 allows remote attackers to execute arbitrary SQL commands…EPSS 4.1%6.5CVE-2017-14537Netfortris trixbox path traversal vulnerabilitytrixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.…EPSS 39%5.4CVE-2017-14536Netfortris trixbox cross-site scripting vulnerabilitytrixbox 2.8.0.4 has XSS via the PATH_INFO to /maint/index.php or /user/includes/language/langChooser.php.EPSS 0.60%5.0CVE-2014-5111Netfortris trixbox path traversal vulnerabilityMultiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parame…EPSS 22%4.3CVE-2014-5110Netfortris trixbox cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in user/help/html/index.php in Fonality trixbox allows remote attackers to inject arbitrary web script or HT…EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2017-14535), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.