Collax Security Gateway: cross-site request forgery in rrd2csv.cgi leads to Perl code execution and root compromise
A single click by a logged-in administrator, or any delegated sub-admin directly, reaches Perl code execution as admin and then root through the unvalidated plugin parameter.
Advisory ID: TP-2026-066
Product: Collax Security Gateway (German UTM, firewall, mail and SSL-VPN appliance; also affects Collax Business Server and Groupware Suite)
Vulnerability type: Cross-site request forgery leading to code execution (CWE-352)
CVE: pending (MITRE CNA-LR)
CVSS 3.1: 8.3 (High) · CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Vendor advisory: Collax release notes CSG 7.2.48
Affected versions: 7.2.46 and earlier
Fixed in: 7.2.48
Reported: 01 September 2026
Summary
The admin web interface (adminhttpd on tcp/8001) serves rrd2csv.cgi, an RRD graph export helper. The CGI reads the plugin query parameter (cgi-bin/rrd2csv.cgi:75) and passes it unchanged into eval "require $pluginName" (cgi-bin/rrd2csv.cgi:86), a Perl string eval, with no validation before the eval. The admin CGI framework carries no anti-CSRF token and no Referer or Origin check, and the session cookie has no SameSite attribute, so a browser attaches it on a top-level cross-site GET. Separately, cgi-bin performs no per-role check, so any delegated sub-admin calls the CGI directly. The eval runs as OS user admin; the setuid helper /usr/sbin/suwrap (root:admin, 4750) provides the documented one-hop escalation to root.
Root cause
rrd2csv.cgi reads the plugin query parameter (cgi-bin/rrd2csv.cgi:75) and evaluates eval "require $pluginName" (cgi-bin/rrd2csv.cgi:86) before any ->can() or AKLib::Config->open() guard runs.
The value was meant to name a Perl plugin module, which the code then probes with $pluginName->can("defFor_$series") (:93), so a payload of the form 5;system(...);1 uses the require version-check trick to reach the trailing system(...).
The admin CGI framework carries no CSRF token and no Referer or Origin check, and the session cookie is set without SameSite, so the browser sends it on a top-level cross-site GET.
Apache gates /cgi-bin/* only with Require valid-user / Require user admin, and no CGI performs a per-role check, so a delegated sub-admin reaches the sink directly.
The eval runs as OS user admin (adminhttpd.conf:119-120), and /usr/sbin/suwrap is setuid root:admin mode 4750, giving admin a one-hop path to root.
Proof of Concept
Schematically: the attacker gets a logged-in administrator to open a page that issues a GET to the CGI.
GET /cgi-bin/rrd2csv.cgi?plugin=<require-eval breakout with an OS command>&series=x HTTP/1.1
Host: <gw>:8001
Cookie: admin_session_<host>=<admin session>
The statement-separating semicolon is encoded as %3B because CGI.pm splits the query string on a literal ;. The injected command runs as OS user admin and, through the setuid suwrap helper, as root. Verified on 2026-09-01 with a uid=0(root) marker under chroot+akrun.
Impact
- Arbitrary OS command execution as OS user admin, then root through the shipped setuid suwrap helper.
- Reachable unauthenticated through a single administrator click, since the session cookie has no SameSite and the framework has no CSRF token.
- Reachable directly by any delegated sub-admin, because cgi-bin enforces no per-role check.
- No CSP, X-Frame-Options or X-Content-Type-Options header anywhere on the appliance.
References
Is Something Like This in Your Software?
Our team found this vulnerability during its work. Have your applications tested by the same specialists, with a penetration test from turingpoint.
