Executive brief
FNT Command, a software suite used for managing IT and telecommunications infrastructure, contains a security flaw that allows an authorized user to upload and run malicious code on the server. If exploited, an attacker could gain full control over the system, allowing them to steal sensitive infrastructure data, modify configurations, or disrupt operations. This issue has been resolved in version 13.4.1.
Technical details
FNT Command is vulnerable to an unrestricted file upload (CWE-434) within the C Base Module. The application fails to sufficiently validate the type and content of uploaded files, allowing an authenticated attacker with low-level privileges to upload a malicious payload. By triggering the execution of the uploaded file, the attacker can achieve remote code execution (RCE) with the privileges of the application service. This can lead to a complete compromise of the server, including unauthorized data access and lateral movement within the network. The vulnerability is addressed in version 13.4.1.
Affected products
- FNT Software Command <= 13.4.0
Timeline
- 2024-09: disclosed: Vulnerability reported to vendor
- 2024-10: patched: Vendor published a fix
- 2025-12-15: advisory: NVD publication date