CVE-2025-27234

Severity CVSS v4.0:
HIGH
Type:
CWE-78 OS Command Injections
Publication date:
12/09/2025
Last modified:
15/04/2026

Description

Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution.