organization · 4 records
VulnCheck

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
Attackers are actively exploiting a critical hard-coded JWT signing key vulnerability in the Issabel Framework to execute arbitrary OS commands.

Ruby on Rails releases security patches for critical Active Storage vulnerability
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads.

Vulnerability identified in ZBT router firmware allows unauthorized root access
VulnCheck disclosed two factory implants, SPEAKINGSTONE and DARKLANTERN, in firmware for Shenzhen Zhibotong Electronics routers that allow unauthenticated remote attackers root access.

Security vulnerability discovered in DD-WRT router UPnP functionality
CVE-2021-27137 disclosed: An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticated remote attacker to send a request that would ove