FaceSentry Access Control System Command Injection Vulnerability

Vulnerability

A command injection vulnerability has been identified in the FaceSentry Access Control System version 6.4.8. This vulnerability allows authenticated users to inject and execute arbitrary shell commands with root privileges. The issue arises in the 'pingTest.php' and 'tcpPortTest.php' scripts, where unsanitized input parameters can be exploited. The vulnerability is present in several different builds of the FaceSentry firmware.

Impact

Exploitation of this vulnerability allows for authenticated users to execute arbitrary commands as the root user, potentially leading to unauthorized system access or control.

Reproduction

The vulnerability can be reproduced by sending a POST request to 'pingTest.php' or 'tcpPortTest.php' with crafted 'strInIP' and 'strInPort' parameters. The default session cookie must be included in the request. The injected commands will be executed with root privileges, and the results can be retrieved from the web server.

Added: Dec 24, 2025, 8:29 PM
Updated: Dec 24, 2025, 9:34 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
6.2
remediation
0.0
relevance
1.6
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.