CVE-2008-5810
WBPublish (aka WBPublish.exe) in Fujitsu-Siemens WebTransactions 7.0, 7.1, and possibly other versions allows remote attackers to execute arbitrary commands via shell metacharacters in input that i...
Affects 1 product across 1 vendor.
Software does not validate or incorrectly validates input, allowing attackers to craft data processed in unintended ways.
Show all 51
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
CVE-2008-5810 affects WBPublish in Fujitsu-Siemens WebTransactions 7.0 and 7.1, allowing remote attackers to execute arbitrary commands through HTTP requests. This vulnerability has a CVSS score of 10.0, indicating critical severity.
BSID: BS-2009-GLOBAL-325414-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2008-5810?
What is the CVSS score for CVE-2008-5810?
Is CVE-2008-5810 actively exploited?
How do I remediate CVE-2008-5810?
What systems are affected by CVE-2008-5810?
What NERC-CIP standard applies to CVE-2008-5810?
What IEC 62443 requirement maps to CVE-2008-5810?
| CVE ID | CVE-2008-5810 |
|---|---|
| BSID | BS-2009-GLOBAL-325414-C BreachSpider Global ID |
| CVSS Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| Published | 2009-01-02 |
| Last Modified | 2026-04-23 |
| ICS Relevance | 0% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
WBPublish (aka WBPublish.exe) in Fujitsu-Siemens WebTransactions 7.0, 7.1, and possibly other versions allows remote attackers to execute arbitrary commands via shell metacharacters in input that is sent through HTTP and improperly used during temporary session data cleanup, possibly related to (1) directory names, (2) template names, and (3) session IDs.
Source: NIST NVD / MITRE CVE Database
The vulnerability arises from improper handling of shell metacharacters in input sent through HTTP, which can be exploited to execute arbitrary commands during temporary session data cleanup. The attack vector includes directory names, template names, and session IDs.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Fujitsu-Siemens | Webtransactions | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement strict input validation and sanitization for all inputs processed by WBPublish, particularly for directory names, template names, and session IDs. Consider using a web application firewall (WAF) to filter out suspicious requests.
This CVE violates CIP-007-R2 because it allows unauthorized access to electronic security perimeters, potentially leading to the execution of arbitrary commands on critical systems.
This CVE maps to SR 7.6 as it involves the protection against malicious software and unauthorized access, which is essential for maintaining the integrity and availability of industrial control systems.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 142fd6bb399fba67c5b260a1633a4aca2232789ef4df07fc59457acef2fd22388d738e87da08804a39ba2b7d525b33c79981a58f7618df1c2a0634535eb90ddc |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →