CVE-2026-105134
Ahsay AhsayCBS Replication Receiver UpdateReceivers.do os command injection
CVSS Score
10.0
EPSS Score
0.0%
EPSS Percentile
0th
A flaw has been found in Ahsay AhsayCBS up to 10.3.2. This vulnerability affects unknown code of the file /rps/api/json/UpdateReceivers.do of the component Replication Receiver. Executing a manipulation of the argument random can lead to os command injection. It is possible to launch the attack remotely. The exploit has been published and may be used. Upgrading to version 10.3.4 is able to resolve this issue. Upgrading the affected component is advised.
| CWE | CWE-78 CWE-77 |
| Vendor | ahsay |
| Product | ahsaycbs |
| Published | Oct 4, 2026 |
Stay Ahead of the Next One
Get instant alerts for ahsay ahsaycbs
Be the first to know when new critical vulnerabilities affecting ahsay ahsaycbs are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Ahsay / AhsayCBS
10.3.0 10.3.1 10.3.2
References
Credits
๐ nickc (VulDB User) VulDB Vulnerability Moderation Team