CVE-2012-10041Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

WAN Emulator v2.3 contains two unauthenticated command execution vulnerabilities. The result.php script calls shell_exec() with unsanitized input from the pc POST parameter, allowing remote attackers to execute arbitrary commands as the www-data user. The system also includes a SUID-root binary named dosu, which is vulnerable to command injection via its first argument. An attacker can exploit both flaws in sequence to achieve full remote code execution and escalate privileges to root.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-07: 1Technical Details · 2026-04-07: 104-07
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2012-10041: WAN E... Unauthenticated RCE chained with SUID privesc to root via shell_exec() and dosu binary - classic network appliance nightmare. #RCE #privesc #SUID. https://zerodaysignal.com/vulnerability/CVE-2012-10041 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2012-10041, outlining an unauthenticated RCE that can be chained with SUID privilege escalation through shell_exec() and the dosu binary, but it provides no proof of concept, exploit code, patch, or evidence of active exploitation.

    0000051
    204 followersView on X

Explore more