Junglewise Threat Intelligence

CVE-2026-12104: SIMA GmbH Bondix Server OS command injection in tunnel configuration

CVE-2026-12104 · Severity: info · CVSS 8.6 · Published 2026-06-19

Executive brief

SIMA GmbH Bondix Server, a software solution for bonding multiple internet connections into a single high-speed link, contains a vulnerability in its configuration interface. An authorized user with administrative permissions can input malicious commands into the system's configuration settings, allowing them to take full control of the underlying Linux server. This could lead to a complete compromise of the server, data theft, or disruption of network services.

Technical details

An OS command injection vulnerability (CWE-78) exists in the environment and tunnel configuration functionality of Bondix Server on Linux. The flaw is rooted in the improper neutralization of special elements within configuration values that are subsequently passed to server-side scripts. An attacker must be authenticated and possess high privileges (configuration write access) to exploit this vulnerability. Successful exploitation allows for arbitrary command execution with the privileges of the server process. The issue is resolved in Bondix Server version 1.25.7.6.

Affected products

  • SIMA GmbH Bondix Server through 1.25.7.5

Timeline

  • 2026-06-11: patched: Version 1.25.7.6 released
  • 2026-06-18: advisory: Initial advisory published by SIMA GmbH
  • 2026-06-19: disclosed: CVE published to NVD dataset

References