CVE-2026-26280
sebhildebrandt systeminformation, Red Hat Developer Hub
systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection vulnerability in the `wifiNetworks()` function allows an attacker to execute arbitrary OS commands via an unsanitized network interface parameter in the retry code path. In `lib/wifi.js`, the `wifiNetworks()` function sanitizes the `iface` parameter on the initial call (line 437). However, when the initial scan returns empty results, a `setTimeout` retry (lines 440-441) calls `getWifiNetworkListIw(iface)` with the **original unsanitized** `iface` value, which is passed dire...
- CVSS
- 7.8
- EPSS
- 1.23% 66.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.02.20