Gammu SMSD flaw lets attackers execute commands by sending a text message

A high-severity OS command injection vulnerability (GHSA-9vjj-v46c-c5qf) has been discovered in Gammu SMSD, a widely used SMS gateway daemon. The flaw exists in the Files backend when RunOnReceive is enabled: the SMS sender ID was sanitised to produce a safe filename but not a safe shell token, allowing shell metacharacters to pass through. Because the resulting filename is appended directly to a shell command line, a remote, unauthenticated attacker can execute arbitrary code simply by sending a crafted text message with a malicious alphanumeric sender ID. The vulnerability affects systems used for hospital paging, monitoring alerts, and two-factor authentication setups, running commands with the daemon's privileges. The issue is rated High (CVSS 8.1) and has been patched in Gammu version 1.43.3, published 25 July 2026.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in