CVE-2013-7418: Ipcop

Medium severity, CVSS 6.5. EPSS: 2.6% chance of exploitation in the next 30 days.

cgi-bin/iptablesgui.cgi in IPCop (aka IPCop Firewall) before 2.1.5 allows remote authenticated users to execute arbitrary code via shell metacharacters in the TABLE parameter. NOTE: this can be exploited remotely by leveraging a separate cross-site scripting (XSS) vulnerability.

Affected products

  • Ipcop Ipcop: up to and including 2.1.4

Published 2015-01-02. Last modified 2026-06-17.