Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

E-Mail Security Virtual Appliance Command Injection Vulnerability in learn-msg.cgi

Vulnerability

A command injection vulnerability has been identified in the E-Mail Security Virtual Appliance (ESVA) version ESVA_2057. The vulnerability resides in the learn-msg.cgi script, where the CGI handler fails to properly sanitize user input provided through the id parameter. This oversight allows unauthenticated attackers to inject and execute arbitrary shell commands on the underlying system. The exploitation of this vulnerability requires no authentication, leading to full command execution.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the server where ESVA is running.

Reproduction

To reproduce this vulnerability, send a GET request to the '/cgi-bin/learn-msg.cgi' endpoint with an injected command in the 'id' parameter. The injection can be verified by including a command that echoes back output, such as 'echo test'. If the response includes the echoed text, the vulnerability has been successfully exploited.

Added: Aug 8, 2025, 7:37 PM
Updated: Aug 8, 2025, 8:58 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
9.1
remediation
0.0
relevance
0.3
threat
9.1
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.