CVE-2026-40456

An OS Command Injection vulnerability exists in LMS (LAN Management System) before commit 9fcb4de due to an IP address parameter being passed to the "exec()" function without proper validation, allowing attackers to execute arbitrary operating system commands.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-06-18 14:17

Updated : 2026-06-22 17:49


NVD link : CVE-2026-40456

Mitre link : CVE-2026-40456

CVE.ORG link : CVE-2026-40456


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')