### [CVE-2019-7670](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-7670) ![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen) ### Description Prima Systems FlexAir, Versions 2.3.38 and prior. The application incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component, which could allow attackers to execute commands directly on the operating system. ### POC #### Reference - http://packetstormsecurity.com/files/155271/FlexAir-Access-Control-2.3.38-Remote-Root.html - http://packetstormsecurity.com/files/155271/FlexAir-Access-Control-2.3.38-Remote-Root.html #### Github No PoCs found on GitHub currently.