Algo 8028 Control Panel Command Injection Vulnerability Allowing Remote Code Execution

Vulnerability

A command injection vulnerability has been identified in the Algo 8028 Control Panel, specifically in version 3.3.3. The issue resides within the fm-data.lua endpoint, where authenticated attackers can exploit the 'source' parameter to inject commands. These commands are executed with root privileges, facilitating remote code execution via a crafted POST request.

Impact

Exploitation of this vulnerability allows for remote code execution on the affected system, with the injected commands being executed as the root user.

Reproduction

To reproduce this vulnerability, an authenticated user must send a POST request to the fm-data.lua endpoint. The request must include a command injection payload in the 'source' parameter, such as a command to echo the output of a command ID request into a text file on the server. After the command is executed, the user can retrieve the output by accessing the text file through the web server.

Remediation

Users are advised to update to the latest version of the Algo 8028 Control Panel. Firmware update notifications can be subscribed to via the Algo website.

Added: Jan 14, 2026, 12:27 AM
Updated: Jan 14, 2026, 12:27 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.6
remediation
0.0
relevance
2.0
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.