A vulnerability was found in DefaultFuction Content-Management-System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/tools.php. The manipulation of the argument host results in command injection.
This vulnerability is identified as CVE-2026-5333. The attack can be executed remotely. Additionally, an exploit exists.