CVE-2025-50974 | IPFire 2.29 Calamaris log exporter CGI calamaris.dat os command injection
A vulnerability marked as critical has been reported in IPFire 2.29. The impacted element is an unknown function of the file /cgi-bin/logs.cgi/calamaris.dat of the component Calamaris log exporter CGI. This manipulation of the argument BYTE_UNIT/DAY_BEGIN/DAY_END/HIST_LEVEL/MONTH_BEGIN/MONTH_END/NUM_CONTENT/NUM_DOMAINS/NUM_HOSTS/NUM_URLS/PERF_INTERVAL/YEAR_BEGIN/YEAR_END causes os command injection.
This vulnerability appears as CVE-2025-50974. The attack may be initiated remotely. There is no available exploit.