CVE-2024-58287: Yogeshojha Rengine

High severity, CVSS 8.8. EPSS: 3.4% chance of exploitation in the next 30 days.

reNgine 2.2.0 contains a command injection vulnerability in the nmap_cmd parameter of scan engine configuration that allows authenticated attackers to execute arbitrary commands. Attackers can modify the nmap_cmd parameter with malicious base64-encoded payloads to achieve remote code execution during scan engine configuration.

Affected products

Published 2025-12-11. Last modified 2026-06-17.