Executive brief
Profelis SambaBox, a network management and directory service appliance, contains a security vulnerability that allows for code injection. An attacker with high-level administrative privileges can execute unauthorized commands on the underlying operating system. This could lead to a complete takeover of the appliance, resulting in the theft of sensitive data or a total disruption of network authentication services.
Technical details
A code injection vulnerability (CWE-94) in Profelis SambaBox versions 5.1 through 5.2 allows for OS Command Injection. The flaw exists due to improper validation of input that is subsequently used to generate or execute code. An attacker requires network connectivity and high-level administrative privileges (PR:H) to exploit this vulnerability. Successful exploitation enables the execution of arbitrary commands with the privileges of the application, potentially leading to full system compromise. The issue is addressed in version 5.3.
Affected products
- Profelis Information and Consulting Trade and Industry Limited Co SambaBox 5.1 to 5.3 (exclusive)
Timeline
- 2026-05-04: disclosed
- 2026-05-04: advisory