Back

HIGH

VA MAX 8.3.4 Remote Code Execution via changeip.php

Published Apr 5, 2026

Description

VA MAX 8.3.4 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by injecting shell metacharacters into the mtu_eth0 parameter. Attackers can send POST requests to the changeip.php endpoint with malicious payload in the mtu_eth0 field to execute commands as the apache user.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Apr 5, 2026
Updated Apr 6, 2026
Reserved Apr 5, 2026
CISA Vulnrichment
Updated Apr 6, 2026
NVD
Status Deferred
Modified Jul 24, 2026
Red Hat
Severity n/a
Public date n/a