#commandinjection — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #commandinjection, aggregated by home.social.
-
TP-Link patched 5 TP-Link router vulnerabilities in ISP-managed mesh, router, and modem lines, including auth bypass and command injection.
#TPLink #RouterSecurity #CVE #AuthBypass #CommandInjection #IoT #Cybersecurity
-
Ubiquiti's UniFi security advisory 066 patches 25 flaws, including a critical command injection (CVE-2026-50746) scoring 10.0. Update your devices now.
#Ubiquiti #UniFi #UniFiOS #UniFiProtect #CommandInjection #CyberSecurity
-
Ubiquiti's UniFi security advisory 066 patches 25 flaws, including a critical command injection (CVE-2026-50746) scoring 10.0. Update your devices now.
#Ubiquiti #UniFi #UniFiOS #UniFiProtect #CommandInjection #CyberSecurity
-
🚨 CRITICAL: CVE-2026-20266 in Splunk AI Toolkit 5.7 lets admins run arbitrary OS commands due to unsafe shell execution. Restrict admin roles & monitor for abuse until patched. Details: https://radar.offseq.com/threat/cve-2026-20266-the-software-constructs-all-or-part-32c0ef3d9fc0383c #OffSeq #Splunk #Vuln #CommandInjection
-
“How do we parse that data? Let’s mess with it a little so it becomes code and then we can run it.”
Hasn’t been a good idea back when people used this approach to “parse” JSON, still isn’t a good idea now…
-
“How do we parse that data? Let’s mess with it a little so it becomes code and then we can run it.”
Hasn’t been a good idea back when people used this approach to “parse” JSON, still isn’t a good idea now…
-
GitHub Flaw Exposes Remote Code Execution to Authenticated Users
A single git push command was all it took to exploit a flaw in GitHub's internal protocol, allowing authenticated users to execute code on backend infrastructure. This shocking vulnerability, tracked as CVE-2026-3854, highlights the potential for devastating remote code execution attacks.
#RemoteCodeExecution #Github #Cve20263854 #CommandInjection #SupplyChain
-
SGLang Flaw Enables Remote Code Execution via Malicious Model Files
A single malicious file can become a powerful gateway for attackers to run arbitrary commands on vulnerable machines - and a newly disclosed flaw in SGLang, CVE-2026-5760, reveals just how easily this can happen through specially crafted GGUF model files. This highly severe vulnerability, scoring 9.8 out of 10.0, enables remote code…
#RemoteCodeExecution #Cve20265760 #CommandInjection #Gguf #Sglang
-
Mirai Botnet Targets TP-Link Routers via CVE-2023-33538 Exploits
Your home router could be a ticking time bomb, vulnerable to exploitation by malicious actors - in fact, a known weakness (CVE-2023-33538) in TP-Link routers has already been targeted by the notorious Mirai botnet. Is your small but mighty box at risk of becoming a launchpad for someone else's agenda?
#MiraiBotnet #Cve202333538 #TplinkRouters #CommandInjection #IotVulnerabilities
-
PHP Composer Flaws Expose Code Execution Risk, Prompting Patches
Critical flaws in PHP Composer, a popular package manager, leave countless websites vulnerable to code execution attacks - but fortunately, patches have been released to swiftly mitigate this risk. If exploited, these high-severity vulnerabilities could allow hackers to execute arbitrary commands, putting entire…
#PhpComposer #CodeExecution #PackageManager #CommandInjection #VulnerabilityManagement
-
⚠️ CVE-2026-5041 (MEDIUM): Command injection in Chamber of Commerce Membership Mgmt System v1.0 via admin/pageMail.php. High privileges needed, public exploit exists. Input validation & patching advised. https://radar.offseq.com/threat/cve-2026-5041-command-injection-in-code-projects-c-82c5a99c #OffSeq #Vuln #CommandInjection #InfoSec
-
⚠️ CRITICAL: CVE-2025-14707 in Shiguangwu sgwbox N3 v2.0.25 enables unauthenticated RCE via the DOCKER feature. No patch, public exploit available. Restrict network access, monitor logs, and disable if possible. https://radar.offseq.com/threat/cve-2025-14707-command-injection-in-shiguangwu-sgw-931e2bae #OffSeq #CommandInjection #Infosec
-
🚨 CRITICAL: CVE-2025-67511 in aliasrobotics CAI ≤0.5.9 allows remote, unauthenticated command injection via run_ssh_command_with_credentials(). No patch—restrict access, validate input, and monitor closely! https://radar.offseq.com/threat/cve-2025-67511-cwe-77-improper-neutralization-of-s-63820d7d #OffSeq #CommandInjection #AIsecurity #CVE202567511
-
W3 Total Cache Vulnerability Puts Over One Million WordPress Sites at Risk https://thecyberexpress.com/w3-total-cache-cve-2025-9501-wordpress-risk/ #TheCyberExpressNews #commandinjection #TheCyberExpress #FirewallDaily #W3TotalCache #CVE20259501 #CyberNews #CVSS
-
W3 Total Cache Vulnerability Puts Over One Million WordPress Sites at Risk https://thecyberexpress.com/w3-total-cache-cve-2025-9501-wordpress-risk/ #TheCyberExpressNews #commandinjection #TheCyberExpress #FirewallDaily #W3TotalCache #CVE20259501 #CyberNews #CVSS
-
Missing a firmware update on your TP-Link Omada gateway could be like leaving your front door wide open—hackers can run commands on your network with ease. Is your business protected?
#tp-link
#commandinjection
#networksecurity
#firmwareupdate
#cybersecurityrisks -
Missing a firmware update on your TP-Link Omada gateway could be like leaving your front door wide open—hackers can run commands on your network with ease. Is your business protected?
#tp-link
#commandinjection
#networksecurity
#firmwareupdate
#cybersecurityrisks -
Critical Figma MCP Server Flaw Allows Remote Code Execution https://dailydarkweb.net/critical-figma-mcp-server-flaw-allows-remote-code-execution/ #RemoteCodeExecution #DeveloperSecurity #commandinjection #Vulnerability #CyberSecurity #vulnerability #CVE202553967 #Figma #patch #MCP #RCE
-
Critical Figma MCP Server Flaw Allows Remote Code Execution https://dailydarkweb.net/critical-figma-mcp-server-flaw-allows-remote-code-execution/ #RemoteCodeExecution #DeveloperSecurity #commandinjection #Vulnerability #CyberSecurity #vulnerability #CVE202553967 #Figma #patch #MCP #RCE
-
WD My Cloud devices had a tiny flaw with huge impact—a simple HTTP POST request could let hackers take over your data storage. How safe is your network? Dive into the details and learn how to stay secure.
#cve202530247
#wdmycloud
#commandinjection
#iotsecurity
#firmwareupdate -
State hackers exploited a tiny email attachment flaw to take control of a major security gateway—but Libraesva shut it down with an emergency fix in just 17 hours. Curious how one small breach can rock the world of email security?
#libraesva
#cve202559689
#emailsecurity
#commandinjection
#statesponsored
#cybersecurity
#vulnerability
#incidentresponse
#patchmanagement -
Kolejny problem Fortineta – podatne FortiSIEM pod ostrzałem
Mamy wrażenie, że nie tylko nas zaczynają nużyć problemy produktów bezpieczeństwa, zwłaszcza od kilku firm… . Tym razem legendarny badacz SinSinology prezentuje krytyczną podatność (9.8 w skali CVSS w biuletynie bezpieczeństwa producenta) w produkcie dedykowanym dużym organizacjom – FortiSIEM. TLDR: Sprawa nie jest błaha, ponieważ jak informuje Fortinet luka ta...
#WBiegu #CommandInjection #Fortinet #Podatność #Rce #Siem #Websec
https://sekurak.pl/kolejny-problem-fortineta-podatne-fortisiem-pod-ostrzalem/
-
Kolejny problem Fortineta – podatne FortiSIEM pod ostrzałem
Mamy wrażenie, że nie tylko nas zaczynają nużyć problemy produktów bezpieczeństwa, zwłaszcza od kilku firm… . Tym razem legendarny badacz SinSinology prezentuje krytyczną podatność (9.8 w skali CVSS w biuletynie bezpieczeństwa producenta) w produkcie dedykowanym dużym organizacjom – FortiSIEM. TLDR: Sprawa nie jest błaha, ponieważ jak informuje Fortinet luka ta...
#WBiegu #CommandInjection #Fortinet #Podatność #Rce #Siem #Websec
https://sekurak.pl/kolejny-problem-fortineta-podatne-fortisiem-pod-ostrzalem/
-
Zdalne wykonanie kodu bez uwierzytelnienia na Centosie – panel CWP
CentOS Web Panel to darmowe rozwiązanie dostępne na systemach z rodziny CentOS (lub korzystających z RPM), składające się właściwie z dwóch elementów. Oferuje interfejs administratorski do zarządzania serwerem, konfiguracji usług takich jak serwery WWW, poczty e-mail czy DNS. Oprócz tego, na innym porcie udostępniany jest drugi panel dla użytkowników końcowych,...
#WBiegu #Authbypass #Centos #CommandInjection #Cwp #Rce #Websec
https://sekurak.pl/zdalne-wykonanie-kodu-bez-uwierzytelnienia-na-centosie-panel-cwp/
-
Zdalne wykonanie kodu bez uwierzytelnienia na Centosie – panel CWP
CentOS Web Panel to darmowe rozwiązanie dostępne na systemach z rodziny CentOS (lub korzystających z RPM), składające się właściwie z dwóch elementów. Oferuje interfejs administratorski do zarządzania serwerem, konfiguracji usług takich jak serwery WWW, poczty e-mail czy DNS. Oprócz tego, na innym porcie udostępniany jest drugi panel dla użytkowników końcowych,...
#WBiegu #Authbypass #Centos #CommandInjection #Cwp #Rce #Websec
https://sekurak.pl/zdalne-wykonanie-kodu-bez-uwierzytelnienia-na-centosie-panel-cwp/
-
Completed the Command Injections module on HTB Academy - halfway through the Bug Bounty Hunter path! 🚀
https://academy.hackthebox.com/achievement/922218/109
#hackthebox #htbacademy #cybersecurity #infosec #commandinjection #bugbounty #learningjourney
-
~Chińscy hackerzy przeniknęli do komputerów Departamentu Skarbu USA. Włamali się do dostawcy usługi zdalnego dostępu.
Najpierw zhackowali jednego z dostawców – tj. firmę BeyondTrust (zapewniającą w szczególności usługi związane ze zdalnym dostępem). A dokładniej – zhackowali usługę zapewniającą zdalny dostęp… i taki dostęp uzyskali na komputerach m.in. jednego z klientów firmy – tj. Departamentu Skarbu USA. Następnie hackerzy wykradli stamtąd „pewne dane”. W trakcie dochodzenia...
#WBiegu #Apt #Chiny #CommandInjection #Hack #Usa #ZdalnyDostęp
-
~Chińscy hackerzy przeniknęli do komputerów Departamentu Skarbu USA. Włamali się do dostawcy usługi zdalnego dostępu.
Najpierw zhackowali jednego z dostawców – tj. firmę BeyondTrust (zapewniającą w szczególności usługi związane ze zdalnym dostępem). A dokładniej – zhackowali usługę zapewniającą zdalny dostęp… i taki dostęp uzyskali na komputerach m.in. jednego z klientów firmy – tj. Departamentu Skarbu USA. Następnie hackerzy wykradli stamtąd „pewne dane”. W trakcie dochodzenia...
#WBiegu #Apt #Chiny #CommandInjection #Hack #Usa #ZdalnyDostęp
-
BeyondTrust Remote Access & Support Flaw Enables Command Injection Attacks https://cybersecuritynews.com/beyondtrust-remote-access-support-flaw/ #ComputerVulnerabilityNews #InformationSecurityNews #CyberSecurityNews #VulnerabilityNews #CommandInjection #cybersecurity #vulnerability #BeyondTrust
-
BeyondTrust Remote Access & Support Flaw Enables Command Injection Attacks https://cybersecuritynews.com/beyondtrust-remote-access-support-flaw/ #ComputerVulnerabilityNews #InformationSecurityNews #CyberSecurityNews #VulnerabilityNews #CommandInjection #cybersecurity #vulnerability #BeyondTrust
-
CERT-IN Warns About Critical Vulnerabilities in Palo Alto Networks Applications https://thecyberexpress.com/cert-in-vulnerabilities-palo-alto-networks/ #informationdisclosure #privilegeescalation #TheCyberExpressNews #CybersecurityNews #commandinjection #paloaltonetworks #securityadvisory #Vulnerabilities #TheCyberExpress #FirewallDaily #cybersecurity #GlobalProtect #CortexXSOAR #CERTIn #PANOS
-
CERT-IN Warns About Critical Vulnerabilities in Palo Alto Networks Applications https://thecyberexpress.com/cert-in-vulnerabilities-palo-alto-networks/ #informationdisclosure #privilegeescalation #TheCyberExpressNews #CybersecurityNews #commandinjection #paloaltonetworks #securityadvisory #Vulnerabilities #TheCyberExpress #FirewallDaily #cybersecurity #GlobalProtect #CortexXSOAR #CERTIn #PANOS
-
FBI urges software developers to end command injection
https://stackdiary.com/fbi-urges-software-developers-to-end-command-injection/
#Cybersecurity #Software #Coding #Development #Security #FBI #CISA #Tech #Programming #Innovation #Safety #Protection #Hackers #Vulnerabilities #CommandInjection #SecureCode #Digital #Technology #CodingLife #DevOps #SecurityAlert #IT #SoftwareDev #Cyber #DataProtection #OnlineSafety #TechNews #BugBounty #Infosec #TechUpdate #SecureByDesign
-
FBI urges software developers to end command injection
https://stackdiary.com/fbi-urges-software-developers-to-end-command-injection/
#Cybersecurity #Software #Coding #Development #Security #FBI #CISA #Tech #Programming #Innovation #Safety #Protection #Hackers #Vulnerabilities #CommandInjection #SecureCode #Digital #Technology #CodingLife #DevOps #SecurityAlert #IT #SoftwareDev #Cyber #DataProtection #OnlineSafety #TechNews #BugBounty #Infosec #TechUpdate #SecureByDesign
-
Linksys Router Flaw Let Attackers Perform Command Injection, PoC Released https://gbhackers.com/linksys-router-flaw-command-injection/ #VulnerabilityAnalysis #CVE/vulnerability #CyberSecurityNews #CommandInjection #LinksysRouter #Vulnerability #Exploit
-
Linksys Router Flaw Let Attackers Perform Command Injection, PoC Released https://gbhackers.com/linksys-router-flaw-command-injection/ #VulnerabilityAnalysis #CVE/vulnerability #CyberSecurityNews #CommandInjection #LinksysRouter #Vulnerability #Exploit
-
Cisco IMC Command Injection Vulnerability Alert
Date: April 17, 2024
CVE: CVE-2024-20356
Vulnerability Type: Command Injection
CWE: [[CWE-78]]
Sources: Cisco Security AdvisoryIssue Summary
A critical vulnerability has been identified in the Cisco Integrated Management Controller (IMC) web-based management interface. This flaw allows authenticated, remote attackers with Administrator-level privileges to perform command injection attacks, potentially gaining root access to the affected systems. Cisco has acknowledged the vulnerability and provided software updates to mitigate the issue.
Technical Key findings
The vulnerability results from inadequate input validation of command strings by the web-based management interface. Attackers can exploit this by sending specially crafted commands to the interface, which are then executed with elevated privileges.
Vulnerable products
- 5000 Series Enterprise Network Compute Systems (ENCS)
- Catalyst 8300 Series Edge uCPE
- UCS C-Series M5, M6, and M7 Rack Servers (standalone mode)
- UCS E-Series Servers
- UCS S-Series Storage Servers (standalone mode)
Impact assessment
Successful exploitation allows attackers to elevate privileges to root, leading to full system control. This can result in unauthorized access, data leakage, and potential interruption of operations.
Patches or workaround
No workarounds are available. Cisco recommends updating to the latest firmware versions provided in their security advisory to address this vulnerability.
Tags
#Cisco #CVE-2024-20356 #CommandInjection #CIMC #ITSecurity #PatchManagement
-
Cisco IMC Command Injection Vulnerability Alert
Date: April 17, 2024
CVE: CVE-2024-20356
Vulnerability Type: Command Injection
CWE: [[CWE-78]]
Sources: Cisco Security AdvisoryIssue Summary
A critical vulnerability has been identified in the Cisco Integrated Management Controller (IMC) web-based management interface. This flaw allows authenticated, remote attackers with Administrator-level privileges to perform command injection attacks, potentially gaining root access to the affected systems. Cisco has acknowledged the vulnerability and provided software updates to mitigate the issue.
Technical Key findings
The vulnerability results from inadequate input validation of command strings by the web-based management interface. Attackers can exploit this by sending specially crafted commands to the interface, which are then executed with elevated privileges.
Vulnerable products
- 5000 Series Enterprise Network Compute Systems (ENCS)
- Catalyst 8300 Series Edge uCPE
- UCS C-Series M5, M6, and M7 Rack Servers (standalone mode)
- UCS E-Series Servers
- UCS S-Series Storage Servers (standalone mode)
Impact assessment
Successful exploitation allows attackers to elevate privileges to root, leading to full system control. This can result in unauthorized access, data leakage, and potential interruption of operations.
Patches or workaround
No workarounds are available. Cisco recommends updating to the latest firmware versions provided in their security advisory to address this vulnerability.
Tags
#Cisco #CVE-2024-20356 #CommandInjection #CIMC #ITSecurity #PatchManagement
-
Palo Alto Networks #GlobalProtect 0day exploited since at least March 26 - https://www.bleepingcomputer.com/news/security/palo-alto-networks-zero-day-exploited-since-march-to-backdoor-firewalls/ #paloaltonetworks #commandinjection #vulnerability #infosec #cybersecurity #cve20243400
-
Palo Alto Networks #GlobalProtect 0day exploited since at least March 26 - https://www.bleepingcomputer.com/news/security/palo-alto-networks-zero-day-exploited-since-march-to-backdoor-firewalls/ #paloaltonetworks #commandinjection #vulnerability #infosec #cybersecurity #cve20243400
-
🔴 Krytyczny 0day w VPN od PaloAlto (podatność jest wykorzystywana w realnych atakach). CVSS 10/10.
Podatny jest GlobalProtect. „GlobalProtect is more than a VPN. It provides flexible, secure remote access for all users everywhere.” Podatność umożliwia zdobycie roota na urządzeniu PaloAlto – bez konieczności jakiegokolwiek uwierzytelnienia (!). Unauth Command Injection. Producent informuje, że luka jest wykorzystywana w realnych atakach. Podatne są linie: PAN-OS 10.2 /...
-
Critical Command Injection Vulnerability in Palo Alto Networks PAN-OS
Date: 2024-04-12
CVE: CVE-2024-3400
Vulnerability Type: Command Injection
CWE: [[CWE-77]]
Sources: Palo Alto Networks Security Advisory
Exploited in the wild: Yes, Palo Alto Networks is aware of a limited number of attacks that leverage the exploitation of this vulnerability.Issue Summary
A severe command injection vulnerability identified as CVE-2024-3400 affects the GlobalProtect gateway feature of PAN-OS, allowing unauthenticated remote attackers to execute arbitrary code with root privileges. This vulnerability impacts specific versions of PAN-OS (PAN-OS 11.1 < 11.1.2-h3, PAN-OS 11.0 < 11.0.4-h1, PAN-OS 10.2 < 10.2.9-h1) with the configurations for both GlobalProtect gateway and device telemetry enabled.
Technical Key Findings
The vulnerability allows for OS command injection through improperly neutralized special elements in commands. This flaw can be exploited remotely without user interaction due to its network-based attack vector and low complexity.
Vulnerable Products
Affected products include certain versions of PAN-OS 10.2, 11.0, and 11.1 when both GlobalProtect gateway and device telemetry are enabled.
Impact Assessment
Exploitation could lead to complete system compromise, enabling attackers to disrupt operations or steal sensitive information.
Patches or Workarounds
Hotfix releases for affected PAN-OS versions are expected by April 14, 2024. A mitigation through Threat ID 95187 is available for those with Threat Prevention subscriptions, or by temporarily disabling device telemetry until the device is upgraded to a fixed PAN-OS version.
Tags
#PaloAltoNetworks #CVE-2024-3400 #Cybersecurity #CommandInjection #NetworkSecurity
-
Critical Command Injection Vulnerability in Palo Alto Networks PAN-OS
Date: 2024-04-12
CVE: CVE-2024-3400
Vulnerability Type: Command Injection
CWE: [[CWE-77]]
Sources: Palo Alto Networks Security Advisory
Exploited in the wild: Yes, Palo Alto Networks is aware of a limited number of attacks that leverage the exploitation of this vulnerability.Issue Summary
A severe command injection vulnerability identified as CVE-2024-3400 affects the GlobalProtect gateway feature of PAN-OS, allowing unauthenticated remote attackers to execute arbitrary code with root privileges. This vulnerability impacts specific versions of PAN-OS (PAN-OS 11.1 < 11.1.2-h3, PAN-OS 11.0 < 11.0.4-h1, PAN-OS 10.2 < 10.2.9-h1) with the configurations for both GlobalProtect gateway and device telemetry enabled.
Technical Key Findings
The vulnerability allows for OS command injection through improperly neutralized special elements in commands. This flaw can be exploited remotely without user interaction due to its network-based attack vector and low complexity.
Vulnerable Products
Affected products include certain versions of PAN-OS 10.2, 11.0, and 11.1 when both GlobalProtect gateway and device telemetry are enabled.
Impact Assessment
Exploitation could lead to complete system compromise, enabling attackers to disrupt operations or steal sensitive information.
Patches or Workarounds
Hotfix releases for affected PAN-OS versions are expected by April 14, 2024. A mitigation through Threat ID 95187 is available for those with Threat Prevention subscriptions, or by temporarily disabling device telemetry until the device is upgraded to a fixed PAN-OS version.
Tags
#PaloAltoNetworks #CVE-2024-3400 #Cybersecurity #CommandInjection #NetworkSecurity
-
CVE-2024-3400 PAN-OS: OS Command Injection #Vulnerability in #GlobalProtect Gateway
A command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.
This issue will be fixed in hotfix releases of PAN-OS 10.2.9-h1 (ETA: By 4/14), PAN-OS 11.0.4-h1 (ETA: By 4/14), and PAN-OS 11.1.2-h3 (ETA: By 4/14), and in all later PAN-OS versions.
ref: https://security.paloaltonetworks.com/CVE-2024-3400 #paloaltonetworks #commandinjection #vulnerability #infosec #cybersecurity #cve20243400
-
CVE-2024-3400 PAN-OS: OS Command Injection #Vulnerability in #GlobalProtect Gateway
A command injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall.
This issue will be fixed in hotfix releases of PAN-OS 10.2.9-h1 (ETA: By 4/14), PAN-OS 11.0.4-h1 (ETA: By 4/14), and PAN-OS 11.1.2-h3 (ETA: By 4/14), and in all later PAN-OS versions.
ref: https://security.paloaltonetworks.com/CVE-2024-3400 #paloaltonetworks #commandinjection #vulnerability #infosec #cybersecurity #cve20243400
-
Wall-Escape Vulnerability Analysis: Implications and Mitigation Strategies
Date: February 27, 2024
CVE: CVE-2024-28085
Vulnerability Type: [[Command Injection]]
CWE: [[CWE-77]], [[CWE-78]], [[CWE-88]]
Sources: [SANS Wall-Escape (CVE-2024-28085)](https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txtIssue Summary
Wall-Escape (CVE-2024-28085) unveils a critical flaw in the
wallcommand from the util-linux package, allowing unprivileged users to execute command-line arguments without proper escape sequence filtering. This vulnerability has existed since 2013, posing a significant risk on systems wherewallis setgid andmesgis set to 'y', notably Ubuntu 22.04 and Debian Bookworm.Technical Key findings
The flaw arises from the mishandling of command-line arguments (
argv), which are not sanitized for escape sequences. This oversight enables attackers to inject arbitrary text onto terminals of other users, potentially leading to information leakage or clipboard alteration. The vulnerability is exploitable through craftedwallcommand executions, leveraging system features to extract sensitive information such as user passwords.Vulnerable products
- All versions of util-linux since 2013
- Specifically impactful on:
- Ubuntu 22.04
- Debian Bookworm
Impact assessment
Successful exploitation can lead to unauthorized information disclosure and manipulation of terminal sessions. On Ubuntu 22.04, attackers can deceive users into revealing passwords. The vulnerability also enables clipboard content alteration on certain terminal emulators.
Patches or workaround
No specific patches were mentioned for CVE-2024-28085. Users are advised to restrict access to the
wallcommand and monitor systems for unusual terminal behavior indicative of exploitation attempts.Tags
#CVE-2024-28085 #CommandInjection #Ubuntu #Debian #InformationDisclosure #util-linux #TerminalSecurity
-
Wall-Escape Vulnerability Analysis: Implications and Mitigation Strategies
Date: February 27, 2024
CVE: CVE-2024-28085
Vulnerability Type: [[Command Injection]]
CWE: [[CWE-77]], [[CWE-78]], [[CWE-88]]
Sources: [SANS Wall-Escape (CVE-2024-28085)](https://people.rit.edu/sjf5462/6831711781/wall_2_27_2024.txtIssue Summary
Wall-Escape (CVE-2024-28085) unveils a critical flaw in the
wallcommand from the util-linux package, allowing unprivileged users to execute command-line arguments without proper escape sequence filtering. This vulnerability has existed since 2013, posing a significant risk on systems wherewallis setgid andmesgis set to 'y', notably Ubuntu 22.04 and Debian Bookworm.Technical Key findings
The flaw arises from the mishandling of command-line arguments (
argv), which are not sanitized for escape sequences. This oversight enables attackers to inject arbitrary text onto terminals of other users, potentially leading to information leakage or clipboard alteration. The vulnerability is exploitable through craftedwallcommand executions, leveraging system features to extract sensitive information such as user passwords.Vulnerable products
- All versions of util-linux since 2013
- Specifically impactful on:
- Ubuntu 22.04
- Debian Bookworm
Impact assessment
Successful exploitation can lead to unauthorized information disclosure and manipulation of terminal sessions. On Ubuntu 22.04, attackers can deceive users into revealing passwords. The vulnerability also enables clipboard content alteration on certain terminal emulators.
Patches or workaround
No specific patches were mentioned for CVE-2024-28085. Users are advised to restrict access to the
wallcommand and monitor systems for unusual terminal behavior indicative of exploitation attempts.Tags
#CVE-2024-28085 #CommandInjection #Ubuntu #Debian #InformationDisclosure #util-linux #TerminalSecurity
-
"🚨 #QNAPAlert: Multiple Vulnerabilities Unveiled Across QNAP Devices 🚨"
Recent security advisories highlight critical vulnerabilities in QNAP NAS systems, potentially affecting thousands of users globally. These flaws range from command injection to SQL injection. 🛡️💻
Highlights:
- QSA-23-47 addresses a command injection vulnerability, enabling attackers to execute arbitrary commands.
- QSA-23-30 and QSA-24-03 reveal OS injection and improper access control issues.
- QSA-24-05 warns of an OS command and SQL injection vulnerability flaw, granting authenticated users to inject malicious code via a network vector.
Mitigation: Users are urged to update their devices immediately to the latest firmware to protect against these vulnerabilities.
Tags: #CyberSecurity #Vulnerability #QNAP #NAS #CommandInjection #SQLInjection #DataProtection #FirmwareUpdate 🛠️🔐
Source: QNAP Security Advisories & HKCERT Bulletin
-
"🔥 pfSense Security Alert: Critical Vulnerabilities Uncovered by SonarCloud 🛡️"
SonarCloud's vigilant scanning reveals two critical vulnerabilities in pfSense, a widely used open-source firewall: XSS (CVE-2023-42325) and Command Injection (CVE-2023-42326). These vulnerabilities, if exploited, could allow attackers to execute arbitrary commands on pfSense appliances, highlighting the importance of continuous security vigilance even within trusted network perimeters. Thanks to swift action by Netgate, patches are now available. A reminder to always keep your systems updated!
📚 Source: Oskar Zeino-Mahmalat's article on SonarSource SonarSource Blog
Tags: #pfSense #Cybersecurity #Vulnerabilities #XSS #CommandInjection #Netgate #SonarCloud #SecurityPatch 🚨🔒💻
-
The advisory of the authenticated command injection I found on Cacti 1.2.24 has been published (CVE-2023-39362).
https://github.com/Cacti/cacti/security/advisories/GHSA-g6ff-58cj-x3cp
#security #cybersecurity #websecurity #appsec #applicationsecurity #hacking #responsibledisclosure #exploit #cacti #rce #commandinjection #remotecommandexecution #cve202339362
-
It's quite fun seeing more and more argument injection attacks popping up in the wild. This time it's tcpdump: https://seclists.org/fulldisclosure/2021/Aug/21
-
:hacker_z: :hacker_o: :hacker_d: :hacker_s: :hacker_e: :hacker_c: 0xD :verified: @[email protected] ·Command Injection - I have just completed this room! Check it out: tryhackme.com/room/oscommandinjection #tryhackme #commandinjection #web #vulnerability #webapp #module #rce #remotecodeexecution #payload #blindcommandinjection #verbosecommandinjection #oscommandinjection via @RealTryHackMe
-
:hacker_z: :hacker_o: :hacker_d: :hacker_s: :hacker_e: :hacker_c: 0xD :verified: @[email protected] ·Some command injection this cool breezy morning. #tryhackme #thm #z0ds3c #commandinjection #hacking #webhacking
-
I've had my first :github: CodeQL query merged into the experimental section of the official CodeQL rules!
https://lnkd.in/dk_tTiQZ (and a "local" variant, https://lnkd.in/dP88QJwa).
That's query ids java/command-line-injection-extra and java/command-line-injection-extra-local
They spot something the existing :java: command injection query does, but in a way that's more robust to unusual code.
It’s an edge case, but one that was important to a customer.