Passy Command Injection Vulnerability Allowing Remote Code Execution

Vulnerability

A command injection vulnerability has been identified in Passy version 1.6.3. This issue allows remote authenticated attackers to execute arbitrary commands by injecting special characters into form input fields to chain multiple commands together. The application operates with root privileges, posing a significant security risk. Exploitation of this vulnerability could enable an attacker to physically open controlled gates by sending unauthorized commands through the serial interface, using a specific code sequence.

Impact

Exploitation of this vulnerability allows for remote code execution with root privileges, creating a critical security risk by enabling unauthorized access and control over the system.

Added: Jan 5, 2026, 7:17 PM
Updated: Jan 5, 2026, 7:17 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.1
remediation
0.0
relevance
1.9
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.