Code Execution

SSD Advisory – TG8 Firewall PreAuth RCE and Password Disclosure

TL;DR Find out how vulnerabilities in TG8 Firewall allows remote unauthenticated users to execute arbitrary code on the remote device as well as disclose the passwords of existing accounts. Vulnerability Summary Two security vulnerabilities in TG8 Firewall have been found allowing a remote user to execute commands as root user without needing to authenticate with …

SSD Advisory – TG8 Firewall PreAuth RCE and Password Disclosure Read More »

SSD Advisory – Hongdian H8922 Multiple Vulnerabilities

TL;DR Find out how multiple vulnerabilities in Hongdian H8922 allow an attacker to run arbitrary commands on the device with root privileges as well as access the device with root privileges via a backdoor account. Vulnerability Summary The H8922 “4G industrial router is based on 3G/4G wireless network and adopts a high-performance 32-bit embedded operating …

SSD Advisory – Hongdian H8922 Multiple Vulnerabilities Read More »

SSD Advisory – OverlayFS PE

TL;DR Find out how a vulnerability in OverlayFS allows local users under Ubuntu to gain root privileges. Vulnerability Summary An Ubuntu specific issue in the overlayfs file system in the Linux kernel where it did not properly validate the application of file system capabilities with respect to user namespaces. A local attacker could use this …

SSD Advisory – OverlayFS PE Read More »

SSD Advisory – QNAP Pre-Auth CGI_Find_Parameter RCE

TL;DR Find out how a memory corruption vulnerability can lead to a pre-auth remote code execution on QNAP QTS’s Surveillance Station plugin. Vulnerability Summary QNAP NAS with “Surveillance Station Local Display function can perform monitoring and playback by using an HDMI display to deliver live Full HD (1920×1080) video monitoring”. Insecure use of user supplied …

SSD Advisory – QNAP Pre-Auth CGI_Find_Parameter RCE Read More »

SSD Advisory – DD-WRT UPNP Buffer Overflow

TL;DR Find out how a vulnerability in DD-WRT allows an unauthenticated attacker to overflow an internal buffer used by UPNP and trigger a code execution vulnerability. Vulnerability Summary DD-WRT is “is Linux-based firmware for wireless routers and access points. Originally designed for the Linksys WRT54G series, it now runs on a wide variety of models”. …

SSD Advisory – DD-WRT UPNP Buffer Overflow Read More »

SSD Advisory – GNU GRUB Command Injection

TL;DR Find out how a vulnerability in GNU GRUB allows users on a Linux system to inject commands into the process of grub-mkconfig which allows them to execute arbitrary commands with elevated privileges. Vulnerability Summary GRUB ships with a script that allows generating /boot/grub/grub.cfg based on the operating systems installed on all the devices attached …

SSD Advisory – GNU GRUB Command Injection Read More »

SSD Advisory – NetMotion Mobility Server Multiple Deserialization of Untrusted Data Lead to RCE

TL;DR Find out how multiple vulnerabilities in NetMotion Mobility Server allow an unauthenticated attacker to run arbitrary code on the server with SYSTEM privileges. Vulnerability Summary NetMotion Mobility is “standards-compliant, client/server-based software that securely extends the enterprise network to the mobile environment. It is mobile VPN software that maximizes mobile field worker productivity by maintaining …

SSD Advisory – NetMotion Mobility Server Multiple Deserialization of Untrusted Data Lead to RCE Read More »

SSD Advisory – Auth Bypass and RCE in Infinite WP Admin Panel

TL;DR Find out how a vulnerability in Infinite WP’s password reset mechanism allows an unauthenticated user to become authenticated and then carry out a Remote Code Execution. Vulnerability Summary InfiniteWP is “free self hosted, multiple WordPress site management solution. It simplifies your WordPress tasks with a click of a button”. A vulnerability in InfiniteWP allows …

SSD Advisory – Auth Bypass and RCE in Infinite WP Admin Panel Read More »

?

Get in touch