CVE Feed

    Dashboard / CVE / CVE-2014-125124

    CVE-2014-125124

    An unauthenticated remote command execution vulnerability exists in Pandora FMS versions up to and including 5.0RC1 via the Anyterm web interface, which listens on TCP port 8023. The anyterm-module endpoint accepts unsanitized user input via the p parameter and directly injects it into a shell command, allowing arbitrary command execution as the pandora user. In certain versions (notably 4.1 and 5.0RC1), the pandora user can elevate privileges to root without a password using a chain involving the artica user account. This account is typically installed without a password and is configured to run sudo without authentication. Therefore, full system compromise is possible without any credentials.

    Published:Jul 31, 2025
    Last Modified:Apr 15, 2026
    EPS:Jul 31, 2025
    EPSS Score:0.36043
    CVSS Score:10

    Affected Products

    Vendor
    Artica
    Product
    Pandora Fms
    Vendor
    Pandora Fms
    Product
    Pandora Fms
    Vendor
    Pandorafms
    Product
    Artica Pandora Fms
    Vendor
    Pandorafms
    Product
    Pandora Fms

    Exploits

    No exploit reference

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High