NewStart CGSL MAIN 7.02 : samba Multiple Vulnerabilities (NS-SA-2026-0095)

critical Nessus Plugin ID 343594

Synopsis

The remote NewStart CGSL host is affected by multiple vulnerabilities.

Description

The remote NewStart CGSL host, running version MAIN 7.02, has samba packages installed that are affected by multiple vulnerabilities:

- A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the print command setting via the %J substitution character without escaping shell meta characters. A remote attacker could exploit this vulnerability by sending a specially crafted print job description that contains unescaped shell characters. This could lead to remote code execution on the affected system. (CVE-2026-4480)

- A flaw was found in Samba, in the front-end WINS hook handling: NetBIOS names from registration packets are passed to a shell without proper validation or escaping. Unsanitized NetBIOS name data from WINS registration packets are inserted into a shell command and executed by the Samba Active Directory Domain Controller's wins hook, allowing an unauthenticated network attacker to achieve remote command execution as the Samba process. (CVE-2025-10230)

- A flaw was found in Samba, in the vfs_streams_xattr module, where uninitialized heap memory could be written into alternate data streams. This allows an authenticated user to read residual memory content that may include sensitive data, resulting in an information disclosure vulnerability. (CVE-2025-9640)

- A flaw was found in Samba's vfs_worm module. The module is intended to provide write-once, read-many (WORM) protections by preventing modification of files after a configurable grace period. Due to insufficient validation during rename operations, an authenticated user with write access to a share could overwrite a protected file by renaming a newly created file over the existing WORM-protected file.
(CVE-2026-2340)

- A flaw was found in Samba's certificate auto-enrollment Group Policy handling. When certificate auto- enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store without proper verification. An attacker with the ability to intercept or redirect network traffic could exploit this behavior to supply a malicious certificate authority certificate, potentially allowing interception or spoofing of trusted communications. (CVE-2026-3012)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade the vulnerable CGSL samba packages. Note that updated packages may not be available yet. Please contact ZTE for more information.

See Also

https://security.gd-linux.com/info/CVE-2025-10230

https://security.gd-linux.com/info/CVE-2025-9640

https://security.gd-linux.com/info/CVE-2026-2340

https://security.gd-linux.com/info/CVE-2026-3012

https://security.gd-linux.com/info/CVE-2026-3238

https://security.gd-linux.com/info/CVE-2026-4408

https://security.gd-linux.com/info/CVE-2026-4480

https://security.gd-linux.com/notice/NS-SA-2026-0095

Plugin Details

Severity: Critical

ID: 343594

File Name: newstart_cgsl_NS-SA-2026-0095_samba.nasl

Version: 1.1

Type: Local

Published: 9/8/2026

Updated: 9/8/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.7

Percentile: 99.07

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-4480

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:zte:cgsl_main:7, p-cpe:/a:zte:cgsl_main:ctdb, p-cpe:/a:zte:cgsl_main:libnetapi-devel, p-cpe:/a:zte:cgsl_main:libnetapi, p-cpe:/a:zte:cgsl_main:libsmbclient-devel, p-cpe:/a:zte:cgsl_main:libsmbclient, p-cpe:/a:zte:cgsl_main:libwbclient-devel, p-cpe:/a:zte:cgsl_main:libwbclient, p-cpe:/a:zte:cgsl_main:python3-samba-dc, p-cpe:/a:zte:cgsl_main:python3-samba-devel, p-cpe:/a:zte:cgsl_main:python3-samba-test, p-cpe:/a:zte:cgsl_main:python3-samba, p-cpe:/a:zte:cgsl_main:samba-client-libs, p-cpe:/a:zte:cgsl_main:samba-client, p-cpe:/a:zte:cgsl_main:samba-common-libs, p-cpe:/a:zte:cgsl_main:samba-common-tools, p-cpe:/a:zte:cgsl_main:samba-common, p-cpe:/a:zte:cgsl_main:samba-dc-bind-dlz, p-cpe:/a:zte:cgsl_main:samba-dc-libs, p-cpe:/a:zte:cgsl_main:samba-dc-provision, p-cpe:/a:zte:cgsl_main:samba-dc, p-cpe:/a:zte:cgsl_main:samba-dcerpc, p-cpe:/a:zte:cgsl_main:samba-devel, p-cpe:/a:zte:cgsl_main:samba-gpupdate, p-cpe:/a:zte:cgsl_main:samba-krb5-printing, p-cpe:/a:zte:cgsl_main:samba-ldb-ldap-modules, p-cpe:/a:zte:cgsl_main:samba-libs, p-cpe:/a:zte:cgsl_main:samba-pidl, p-cpe:/a:zte:cgsl_main:samba-test-libs, p-cpe:/a:zte:cgsl_main:samba-test, p-cpe:/a:zte:cgsl_main:samba-tools, p-cpe:/a:zte:cgsl_main:samba-usershares, p-cpe:/a:zte:cgsl_main:samba-vfs-glusterfs, p-cpe:/a:zte:cgsl_main:samba-vfs-iouring, p-cpe:/a:zte:cgsl_main:samba-winbind-clients, p-cpe:/a:zte:cgsl_main:samba-winbind-krb5-locator, p-cpe:/a:zte:cgsl_main:samba-winbind-modules, p-cpe:/a:zte:cgsl_main:samba-winbind, p-cpe:/a:zte:cgsl_main:samba

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/ZTE-CGSL/release, Host/ZTE-CGSL/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/7/2026

Vulnerability Publication Date: 10/15/2025

Reference Information

CVE: CVE-2025-10230, CVE-2025-9640, CVE-2026-2340, CVE-2026-3012, CVE-2026-3238, CVE-2026-4408, CVE-2026-4480

IAVA: 2025-A-0777-S, 2026-A-0510-S