漏洞情报聚合

CVE-2026-81573 - If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network- origin restrictions. Commands intended only for local or same-network clients can therefore be executed by arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin takeover. - 漏洞详情

漏洞编号:CVE-2026-81573

风险等级:高危

漏洞来源:CVE

CVE 编号:CVE-2026-81573

CNNVD 编号:-

厂商/产品:- / -

影响范围:-

CWE:CWE-284

发布/更新时间:2026-08-27 / 2026-08-27

漏洞描述

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce network-
origin restrictions. Commands intended only for local or same-network clients can therefore be executed by
arbitrary remote peers. An attacker can read potentially sensitive configuration data and overwrite selected values
in Server.ini. This does include the hash of the credentials for the CodeMeter WebAdmin, enabling WebAdmin
takeover.

相关链接

相关漏洞

« 返回首页