Junglewise Threat Intelligence

CVE-2026-89308: Trexom TrxTimeATTENDANCE OS command injection in ping.php

CVE-2026-89308 · Severity: info · CVSS 9.8 · Published 2026-09-15

Executive brief

Trexom TrxTimeATTENDANCE is an attendance and time-tracking system used by organizations to monitor employee presence. An unauthenticated remote attacker can exploit a command injection flaw in the ping.php endpoint to execute arbitrary code on affected systems, potentially leading to complete system compromise and unauthorized access to sensitive HR and operational data.

Technical details

The vulnerability is an OS command injection (CWE-78) in the ping.php endpoint caused by insufficient input validation and sanitization. An unauthenticated remote attacker can send a specially crafted request to the vulnerable endpoint with malicious parameters that are passed unsanitized to system command execution functions, allowing arbitrary OS command execution. This results in remote code execution with the privileges of the web server process. The vulnerability affects TrxTimeATTENDANCE versions 1.0.5 through 1.9.5 inclusive. Patches are available and users are advised to update to the latest version and restrict network exposure of the ping.php endpoint via firewall rules.

Affected products

  • Trexom TrxTimeATTENDANCE 1.0.5 through 1.9.5 inclusive

Timeline

  • 2026-09-15: disclosed: Vulnerability disclosed by CSIRT Italia and Trexom

References