{"id":"CVE-2026-15027","published":"2026-09-23T09:17:07.657","lastModified":"2026-09-24T14:45:22.827","description":"CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary OS commands through the local service interface, resulting in command execution on the victim's local computer.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-78"],"vendors":[],"products":[],"references":[{"url":"https://www.twcert.org.tw/en/cp-139-11214-89281-2.html","tags":[]},{"url":"https://www.twcert.org.tw/tw/cp-132-11213-28a81-1.html","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"CGServiSign is vulnerable to OS Command Injection, allowing unauthenticated attackers to execute arbitrary commands on the victim's local computer.","exploitability":"Exploitation requires诱导受害者访问恶意网页并通过本地服务接口注入任意OS命令，难度较低，前提是受害者访问了恶意链接。","blast_radius":"如果被利用，攻击者可以在受害者的本地计算机上执行任意命令，造成严重后果。","remediation":"禁用CGServiSign的受影响功能。","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","os-command-injection","web","unauthenticated"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-28T08:57:04.298Z"}}