Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-78211: 4MOSAn GCB Doctor allows remote attackers to run commands on the server
CVE-2026-78211 · published 11 days ago
Summary
The GCB Doctor tool from 4MOSAn Security Technology contains a web page that was left in place for testing. Because it does not require any login, an outsider can send specially crafted data to that page and cause the server to execute any command they choose. Remove or disable the test page and apply any available updates to stop this risk.
What to do
- Update 4mosan security technology 4mosan gcb doctor to version 20260621 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| 4mosan security technology | 4mosan gcb doctor | < 20260621 |
Original advisory text
4MOSAn Security Technology|4MOSAn GCB Doctor - OS Command Injection
4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malicious commands through an unremoved ADOdb test page parameter, thereby executing arbitrary system commands on the server.
Severity
9.3
Critical
CVSS 3.1: 9.8 (NVD)
CVSS 4.0: 9.3 (NVD)
Exploitation
EPSS 2%
Type
CWE-78OS Command Injection
Timeline
Published24 Aug 2026
Updated30 Aug 2026
First seen24 Aug 2026
Monitor software like this
Free during beta