LiteSpeed Web Server Enterprise Command Injection Vulnerability Allowing Remote Code Execution

Vulnerability

A command injection vulnerability allowing remote code execution has been identified in LiteSpeed Web Server Enterprise version 5.4.11. This vulnerability exists in the external application configuration interface, where authenticated administrators can inject shell commands through the 'Command' parameter. The injection exploits path traversal and bash command execution.

Impact

Exploitation of this vulnerability allows for authenticated command injection, with the potential for remote code execution on the server.

Reproduction

To reproduce this vulnerability, log into the LiteSpeed Web Server dashboard as an administrator. Navigate to 'Server Configuration' and then to 'External App'. Edit the application settings and set 'Start By Server' to 'Yes (Through CGI Daemon)'. In the 'Command' parameter, inject a payload that includes a path traversal sequence followed by a bash command, such as one that opens a reverse shell. After injecting the command, perform a 'Graceful Restart' to execute the payload.

Added: Jan 23, 2026, 5:33 PM
Updated: Jan 23, 2026, 10:26 PM

Vulnerability Rating

Custom Algorithm
spread
7.6
impact
10.0
exploitability
6.3
remediation
0.0
relevance
2.3
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.