masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.
https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html
https://www.infosecurity-magazine.com/news/new-linux-botnet-evooo1bot-victims/
https://veriti.ai/blog/vulnerable-villain-when-hackers-get-hacked/
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2007-3010
http://www1.alcatel-lucent.com/psirt/statements/2007002/OXEUMT.htm
http://www.vupen.com/english/advisories/2007/3185
http://www.securityfocus.com/bid/25694
http://www.securityfocus.com/archive/1/479699/100/0/threaded
http://www.redteam-pentesting.de/advisories/rt-sa-2007-001.php