Main
Vulnerability Database
Exploits
ID:12936 - Exploit for OS Command Injection in HFS - CVE-2024-39943
ID:12936 - Exploit for OS Command Injection in HFS - CVE-2024-39943
Published: August 19, 2026
Vulnerability identifier: #VU144368
Vulnerability risk: Medium
CVE-ID: CVE-2024-39943
CWE-ID: CWE-78
Exploitation vector: Remote access
Vulnerable software:
HFS
HFS
Link to public exploit:
Vulnerability description
The vulnerability allows a remote user to execute arbitrary commands on the underlying operating system.
The vulnerability exists due to command injection in the execSync command execution logic when executing shell commands. A remote user can send crafted input to execute arbitrary commands on the underlying operating system.
Remediation
Install security update from vendor's website.