CRITICAL
Topsec TopACM HTTP Request nmc_sync.php os command injection
Published Mar 15, 2026
9.3
CRITICALCVSS 4.0
EPSS 4.33%
Description
A weakness has been identified in Topsec TopACM 3.0. Affected by this vulnerability is an unknown functionality of the file /view/systemConfig/management/nmc_sync.php of the component HTTP Request Handler. Executing a manipulation of the argument template_path can lead to os command injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
-
Affected
- 3.0
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-12214 Advisory
- https://my.feishu.cn/docx/EAFFdhzoeodDxfxeazNcxBzCnRf?from=from_copylink exploit
- https://vuldb.com/?ctiid.351077 signaturepermissions-required
- https://vuldb.com/?id.351077 vdb-entrytechnical-description
- https://vuldb.com/?submit.769768 third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-12214 | Advisory | |
| https://my.feishu.cn/docx/EAFFdhzoeodDxfxeazNcxBzCnRf?from=from_copylink | exploit | |
| https://vuldb.com/?ctiid.351077 | signaturepermissions-required | |
| https://vuldb.com/?id.351077 | vdb-entrytechnical-description | |
| https://vuldb.com/?submit.769768 | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulDB
Published Mar 15, 2026
Updated Mar 16, 2026
Reserved Mar 14, 2026
Link CVE-2026-4170
CISA Vulnrichment
Updated Mar 16, 2026
Red Hat
No data
GitHub
No data