CVE detail
CVE-2019-15107
An issue was discovered in Webmin <=1.920. The parameter old in password_change.cgi contains a command injection vulnerability.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 29.4 · diversity 20.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
18 source links · newest first
- The Convergence of Cloud Secrets & AI RiskSentinelOne Labs
initial access points. The top verified exploit paths continue to involve older, critical CVEs, including: Shellshock ( CVE-2014-6271 ) FortiGate SSL VPN credential disclosure ( CVE-2018-13379 ) Pulse Secure VPN arbitrary file read ( CVE-2019-11510 ) Webmin RCE ( CVE-2019-15107 ) Barracuda ESG zero-day backdoor ( CVE-2023-1698 ) Since these vulnerabil
vendorwww.sentinelone.comMay 13, 2026, 6:11 PM A new variant of Mirai — the botnet malware used to launch massive DDoS attacks —has been targeting 13 vulnerabilities in IoT devices connected to Linux servers, according to researchers at Palo Alto Networks’ Unit 42 cybersecurity team. Once the vulnerable devices are compromised by the variant, dubbed V3G4, they can fully controlled by attackers […]
newswww.csoonline.comFeb 17, 2023, 6:04 PM- Mirai V3G4 botnet exploits 13 flaws to target IoT devicesSecurity Affairs
During the second half of 2022, a variant of the Mirai bot, tracked as V3G4, targeted IoT devices by exploiting tens of flaws. Palo Alto Networks Unit 42 researchers reported that a Mirai variant called V3G4 was attempting to exploit several flaws to infect IoT devices from July to December 2022. Below is the list […]
newssecurityaffairs.comFeb 16, 2023, 9:32 PM A recent variant of the Mirai malware has been observed targeting 13 IoT vulnerabilities to ensnare devices into a botnet.
newswww.securityweek.comFeb 16, 2023, 1:56 PMWe observed Mirai variant V3G4 targeting IoT devices in three separate campaigns in 2022.
vendorunit42.paloaltonetworks.comFeb 15, 2023, 2:00 PMSince October 2019, Unit 42 has been tracking a new ECHOBOT variant with 71 unique exploits, 13 of which haven’t been previously seen exploited in the wild prior to this version.
vendorunit42.paloaltonetworks.comDec 13, 2019, 9:56 PM- Roboto, a new P2P botnet targets Linux Webmin serversSecurity Affairs
Security experts discovered a new peer-to-peer (P2P) botnet dubbed Roboto that is targeting Linux servers running unpatched Webmin installs. Researchers at 360Netlab discovered a new P2P botnet, tracked as Roboto, that is targeting Linux servers running unpatched installations of Webmin installs. The experts first spotted the Roboto botnet in August when they detected a suspicious […]
newssecurityaffairs.comNov 21, 2019, 9:26 AM Webmin, the popular open-source web-based interface for Unix admin contained a remote code execution vulnerability for more than a year. Webmin is an open-source web-based interface for system administration for Linux and Unix. It allows users using web browsers to set up user accounts, Apache, DNS, file sharing and much more. News of the day […]
newssecurityaffairs.comAug 20, 2019, 6:40 AM- Webmin Backdoored for Over a YearSecurityWeek
Webmin, the open source web-based interface for managing Linux and UNIX systems, contained a remote code execution vulnerability for more than a year and it’s believed to be an intentional backdoor.
newswww.securityweek.comAug 19, 2019, 5:45 PM No excerpt available.
Mitigationwww.cisa.govAug 16, 2019, 3:15 AM- https://www.exploit-db.com/exploits/47230www.exploit-db.com
No excerpt available.
Exploitwww.exploit-db.comAug 16, 2019, 3:15 AM No excerpt available.
Exploitattackerkb.comAug 16, 2019, 3:15 AM- http://www.webmin.com/security.htmlwww.webmin.com
No excerpt available.
Vendor Advisorywww.webmin.comAug 16, 2019, 3:15 AM - http://www.pentest.com.tr/exploits/DEFCON-Webmin-1920-Unauthenticated-Remote-Command-Execution.htmlwww.pentest.com.tr
No excerpt available.
Exploitwww.pentest.com.trAug 16, 2019, 3:15 AM - http://packetstormsecurity.com/files/154485/Webmin-1.920-Remote-Code-Execution.htmlpacketstormsecurity.com
No excerpt available.
Exploitpacketstormsecurity.comAug 16, 2019, 3:15 AM - http://packetstormsecurity.com/files/154197/Webmin-1.920-password_change.cgi-Backdoor.htmlpacketstormsecurity.com
No excerpt available.
Exploitpacketstormsecurity.comAug 16, 2019, 3:15 AM - http://packetstormsecurity.com/files/154141/Webmin-Remote-Comman-Execution.htmlpacketstormsecurity.com
No excerpt available.
Exploitpacketstormsecurity.comAug 16, 2019, 3:15 AM - http://packetstormsecurity.com/files/154141/Webmin-1.920-Remote-Command-Execution.htmlpacketstormsecurity.com
No excerpt available.
Exploitpacketstormsecurity.comAug 16, 2019, 3:15 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2024-12828CVSS 8.8 · High
Webmin CGI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Webmin. Authent…
- CVE-2020-35606CVSS 8.8 · High
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can execute arbitrary commands with root privileges via vectors i…
- CVE-2019-12840CVSS 8.8 · High
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root privileges via the data parameter to update.cgi.
- CVE-2026-19771CVSS 7.3 · High
A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manip…
- CVE-2026-73667CVSS 8.8 · High
OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates under samples/getting-started/w…
- CVE-2026-73662CVSS 7.6 · High
FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg123 and other allowed players i…