CVE-2019-25243 - FaceSentry 6.4.8 Authenticated Remote Command Injection via Ping Test

CVE-2019-25243 - FaceSentry 6.4.8 Authenticated Remote Command Injection via Ping Test

CVE ID : CVE-2019-25243 Published : Dec. 24, 2025, 8:15 p.m. | 1 hour, 30 minutes ago Description : FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
Dec. 24, 2025
Affected Product: php
Impact: command injection

Source: Telegram CVE Monitor