Vulnerability Description
Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary code via a crafted path that matches the improperly terminated search criteria of rvia's Java search using the find command.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/Wise-Security/CVE-2026-38945
- https://support.raynet.de/
- https://support.raynet.de/hc/en-us/articles/46163206384788-RSEC200967-Java-Detec
- https://github.com/Wise-Security/CVE-2026-38945/blob/main/CVE-2026-38945.sh
FAQ
What is CVE-2026-38945?
CVE-2026-38945 is a vulnerability with a CVSS score of 7.8 (HIGH). Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary code via a crafted path that matches the improperly terminated search criteria of r...
How severe is CVE-2026-38945?
CVE-2026-38945 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-38945?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.