CVE-2022-50909: Algo Solutions Algo 8028

High severity, CVSS 8.8. EPSS: 2.4% chance of exploitation in the next 30 days.

Algo 8028 Control Panel version 3.3.3 contains a command injection vulnerability in the fm-data.lua endpoint that allows authenticated attackers to execute arbitrary commands. Attackers can exploit the insecure 'source' parameter by injecting commands that are executed with root privileges, enabling remote code execution through a crafted POST request.

Affected products

Published 2026-01-13. Last modified 2026-06-17.