CVE-2008-5810

CRITICAL

WBPublish (aka WBPublish.exe) in Fujitsu-Siemens WebTransactions 7.0, 7.1, and possibly other versions allows remote attackers to execute arbitrary commands via shell metacharacters in input that i...

Affects 1 product across 1 vendor.

BCS8.26
CVSS 2.010.0
EPSS3.8%
Percentile89th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-20: Improper Input Validation

Software does not validate or incorrectly validates input, allowing attackers to craft data processed in unintended ways.

Related Attack Patterns (CAPEC)
CAPEC-3 Using Leading 'Ghost' Character Sequences to Bypass Input Filters
via CWE-20
CAPEC-7 Blind SQL Injection
via CWE-20
CAPEC-8 Buffer Overflow in an API Call
via CWE-20
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
via CWE-20
CAPEC-10 Buffer Overflow via Environment Variables
via CWE-20
Show all 51
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20
via CWE-20

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

CVE-2008-5810 affects WBPublish in Fujitsu-Siemens WebTransactions 7.0 and 7.1, allowing remote attackers to execute arbitrary commands through HTTP requests. This vulnerability has a CVSS score of 10.0, indicating critical severity.

BSID: BS-2009-GLOBAL-325414-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2008-5810?
CVE-2008-5810 affects WBPublish in Fujitsu-Siemens WebTransactions 7.0 and 7.1, allowing remote attackers to execute arbitrary commands through HTTP requests. This vulnerability has a CVSS score of 10.0, indicating critical severity.
What is the CVSS score for CVE-2008-5810?
CVE-2008-5810 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 3.8%.
Is CVE-2008-5810 actively exploited?
No confirmed active exploitation of CVE-2008-5810 as of 2026-05-30.
How do I remediate CVE-2008-5810?
Priority: HIGH. Advisory: http://bs2www.fujitsu-siemens.de/update/securitypatch.htm#english PSIRT: [email protected]
What systems are affected by CVE-2008-5810?
CVE-2008-5810 affects: Fujitsu-Siemens.
What NERC-CIP standard applies to CVE-2008-5810?
NERC CIP CIP-007 CIP-007-R2: This CVE violates CIP-007-R2 because it allows unauthorized access to electronic security perimeters, potentially leading to the execution of arbitrary commands on critical systems.
What IEC 62443 requirement maps to CVE-2008-5810?
IEC 62443 SR 7.6: This CVE maps to SR 7.6 as it involves the protection against malicious software and unauthorized access, which is essential for maintaining the integrity and availability of industrial control systems.
Vulnerability Details
CVE IDCVE-2008-5810
BSIDBS-2009-GLOBAL-325414-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2009-01-02
Last Modified2026-04-23
ICS Relevance0%
Weakness (CWE)
Verticals
ICS-OT
SourceNVD
Official Description

WBPublish (aka WBPublish.exe) in Fujitsu-Siemens WebTransactions 7.0, 7.1, and possibly other versions allows remote attackers to execute arbitrary commands via shell metacharacters in input that is sent through HTTP and improperly used during temporary session data cleanup, possibly related to (1) directory names, (2) template names, and (3) session IDs.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability arises from improper handling of shell metacharacters in input sent through HTTP, which can be exploited to execute arbitrary commands during temporary session data cleanup. The attack vector includes directory names, template names, and session IDs.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Fujitsu-Siemens Webtransactions
Remediation
View Vendor Advisory →

Remediation Priority: HIGH

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 6413 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
● Virtual Patch — CITED Relevance SAGE Engine MEDIUM CONFIDENCE

Implement strict input validation and sanitization for all inputs processed by WBPublish, particularly for directory names, template names, and session IDs. Consider using a web application firewall (WAF) to filter out suspicious requests.

SURICATA RULE
alert http $HOME_NET any -> $EXTERNAL_NET any (msg:"CVE-2008-5810 - WBPublish Arbitrary Command Execution Attempt"; flow:established,to_server; content:"/WBPublish.exe"; http_uri; content:"|26|"; http_method; metadata:service http; sid:9100004; rev:1;)
NERC CIP: CIP-007 CIP-007-R2
This CVE violates CIP-007-R2 because it allows unauthorized access to electronic security perimeters, potentially leading to the execution of arbitrary commands on critical systems.
IEC 62443: SR 7.6
This CVE maps to SR 7.6 as it involves the protection against malicious software and unauthorized access, which is essential for maintaining the integrity and availability of industrial control systems.

Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.

SAGE Enrichment Record — provenance & audit hash
ModelQwen/Qwen2.5-72B-Instruct-AWQ
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash142fd6bb399fba67c5b260a1633a4aca2232789ef4df07fc59457acef2fd22388d738e87da08804a39ba2b7d525b33c79981a58f7618df1c2a0634535eb90ddc
Related CVEs affecting Fujitsu-Siemens
CVE-2024-44102 10.0 A vulnerability has been identified in PP TeleControl Server Basic 1000 to 50... CVE-2025-32433 10.0 Erlang/OTP is a set of libraries for the Erlang programming language. Prior t... CVE-2024-30207 10.0 A vulnerability has been identified in SIMATIC RTLS Locating Manager (6GT2780... CVE-2024-32741 10.0 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0).... CVE-2023-29131 10.0 A vulnerability has been identified in SIMATIC CN 4100 (All versions < V2.5)....
View all Fujitsu-Siemens CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →