Executive brief
ConfigServer Security & Firewall (CSF) is a Linux firewall and security application that manages firewall rules and threat detection. An OS command injection vulnerability in the advanced-rule parser allows a remote attacker who controls an allow/deny feed to execute arbitrary commands with root privileges, potentially enabling complete system compromise and unauthorized access to protected networks.
Technical details
This is an OS command injection vulnerability in the advanced-rule parser component of ConfigServer Security & Firewall, caused by insufficient validation of rule data supplied by configured allow/deny feeds. An attacker who controls a feed that CSF is configured to trust can inject arbitrary shell commands into rule data, which are executed with root privileges due to the way the parser processes feed input. The attack requires the victim to have configured CSF to use a malicious or compromised feed source. WebPros has patched this vulnerability in version 16.30; however, other forks and independently maintained versions may remain vulnerable and require independent evaluation.
Affected products
- ConfigServer Security & Firewall versions prior to 16.30 (WebPros fork)
Timeline
- 2026-09-10: disclosed
- 2026-09-10: patched: WebPros released version 16.30 with fix