Executive brief
SonicCloudOrg sonic-agent, a tool used for mobile device testing and management, contains a security flaw in its Android WebSocket Server component. An attacker can remotely execute unauthorized operating system commands by manipulating specific data paths. This could lead to full control over the affected testing environment or unauthorized access to data on connected devices. The product is no longer supported by the developer, and no official fix is expected.
Technical details
An OS command injection vulnerability exists in SonicCloudOrg sonic-agent versions up to and including 2.7.2. The flaw is located within the Android WebSocket Server component, specifically in the handling of the 'path' argument in the AndroidWSServer.java file. A remote attacker with low privileges can exploit this by sending specially crafted requests to the WebSocket server, leading to arbitrary command execution on the underlying host. Public exploit code (PoC) has been disclosed. The vendor has not responded to disclosure attempts, and the product is considered end-of-life (EOL).
Affected products
- SonicCloudOrg sonic-agent up to 2.7.2
Timeline
- 2026-07-12: advisory: Initial disclosure by VulDB and NVD
- 2026-07-12: disclosed: Public exploit code released on GitHub
References
- https://github.com/xpp3901/CVE_APPLY/blob/main/V-S003_SonicAgent_pullFile_CmdInjection_RCE/poc_pullfile_rce.py
- https://github.com/xpp3901/CVE_APPLY/tree/main/V-S003_SonicAgent_pullFile_CmdInjection_RCE
- https://vuldb.com/cve/CVE-2026-15495
- https://vuldb.com/submit/844484
- https://vuldb.com/vuln/377802
- https://vuldb.com/vuln/377802/cti