Executive brief
TeamT5 ThreatSonar Anti-Ransomware, a security solution designed to protect organizations from ransomware attacks, contains a vulnerability that allows an authorized user to gain full control over the system. An attacker who already has basic access to the system's command-line interface can exploit this flaw to execute commands with the highest level of administrative (root) privileges. This could lead to a complete compromise of the security appliance, allowing the attacker to disable protections, access sensitive data, or disrupt business operations.
Technical details
An OS command injection vulnerability (CWE-78) exists in TeamT5 ThreatSonar Anti-Ransomware versions prior to 4.0.0. The flaw allows an authenticated remote attacker who already possesses shell access to inject and execute arbitrary commands. Because the vulnerable component executes these commands with elevated permissions, the attacker can achieve full root-level access on the underlying operating system. This vulnerability is addressed in version 4.0.0 and hotpatch version 20260302.
Affected products
- TeamT5 ThreatSonar Anti-Ransomware versions before 4.0.0
Timeline
- 2026-04-20: disclosed
- 2026-04-20: advisory