Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-60121: Vitec Flamingo 4.12.2 Unauthenticated Command Execution via ping.php
CVE-2026-60121
CVE-2026-60121
Summary
The Vitec Flamingo 4.12.2 software has a security flaw that allows unauthorized access to the system. This means an attacker can execute commands on the system without needing a password, potentially causing harm. Update to the latest version of Vitec Flamingo to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| vitec | flamingo | 4.12.2 |
Original title
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a d...
Original description
Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers to execute arbitrary commands by exploiting a double-evaluation flaw in shell argument handling. The endpoint applies escapeshellarg() to the user-supplied host POST parameter before passing it to a system wrapper, but the wrapper retrieves the decoded value from argv and incorporates it into a second shell_exec() call without escaping, allowing injected commands to execute with root privileges via passwordless sudo.
mitre CVSS3.1
9.8
Vulnerability type
CWE-78
OS Command Injection
- https://damiri.fr/en/cve/CVE-2026-60121 technical-description exploit
- https://www.vitec.com/solutions/iptv-distribution product
- https://www.vulncheck.com/advisories/vitec-flamingo-unauthenticated-os-command-i... third-party-advisory
Published: 13 Jul 2026 · Updated: 17 Jul 2026 · First seen: 13 Jul 2026