Vulnerability record · CVE-2019-12725 · published 19 July 2019
CVE-2019-12725: Zeroshell web interface OS command injection allows unauthenticated RCE
Zeroshell · Zeroshell
Zeroshell 3.9.0 mishandles several HTTP parameters in its web application, allowing OS commands to be injected into them. Because the flaw is reachable without authentication and yields command execution, it is a severe pre-auth remote code execution issue for exposed Zeroshell instances.
Description
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable OS command injection with a 9.8 CVSS score and very high EPSS makes this an urgent exposure for any internet-facing Zeroshell 3.9.0 instance.
What it is
Zeroshell 3.9.0 mishandles several HTTP parameters in its web application, allowing OS commands to be injected into them. Because the flaw is reachable without authentication and yields command execution, it is a severe pre-auth remote code execution issue for exposed Zeroshell instances.
Impact
An unauthenticated attacker can run arbitrary OS commands on the Zeroshell host, leading to full compromise of the appliance and any data or network traffic it handles.
Attack surface
Reached over the network through the Zeroshell web application by sending crafted HTTP requests with malicious parameters. No authentication and no user interaction are required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.89849, 99.78th percentile) and public exploit references exist, including a Packet Storm advisory and a Tarlogic advisory tagged Exploit. This indicates active interest and readily available exploit material.
What to do
- Upgrade Zeroshell to a version later than 3.9.0 if the vendor has released a fix; check the vendor blog for guidance.
- If no patch is available, restrict access to the Zeroshell web interface to trusted management networks only.
- Place the web interface behind a VPN or authenticated reverse proxy so it is not internet-exposed.
- Monitor vendor advisories and apply any hotfix or configuration hardening the vendor publishes.
Detection
- Inspect web server and application logs for HTTP requests containing shell metacharacters (;, |, &&, $(), backticks) in parameters.
- Alert on unexpected child processes spawned by the web server process (e.g., shell or system utilities).
- Monitor for outbound connections or command-and-control traffic originating from the Zeroshell appliance.
- Review authentication and access logs for requests to the web interface from untrusted or external source IPs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-12725 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-12725), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.