Nuvation Energy Multi-Stack Controller OS Command Injection Vulnerability

Vulnerability

An OS command injection vulnerability has been identified in Nuvation Energy's Multi-Stack Controller (MSC) versions prior to 2.5.1. This vulnerability allows for improper neutralization of special elements used in operating system commands, potentially leading to unauthorized command execution on the affected system.

Impact

Exploitation of this vulnerability allows for OS command injection, where an attacker can execute arbitrary commands on the host operating system where the MSC is running.

Remediation

Users are advised to update their Multi-Stack Controller to version 2.5.1 or later. Consult Nuvation's documentation for instructions on enabling authentication on the MSC and setting a strong password. Security-conscious users may also wish to restrict access to the nCloud service if it is not necessary for their operations.

Added: Jan 3, 2026, 1:17 AM
Updated: Jan 3, 2026, 1:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
5.2
remediation
7.7
relevance
1.8
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.