home.social

#cve2025 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cve2025, aggregated by home.social.

fetched live
  1. Security Advisory Summary:
    SolarWinds Serv-U 15.5.4 patches four critical vulnerabilities:
    • CVE-2025-40538 – Broken access control → system admin creation + root RCE
    • Two type confusion flaws → root code execution
    • One IDOR vulnerability → elevated execution

    Attack prerequisites:
    High-privileged access required. Exploitation likely via credential compromise or chained privilege escalation.

    Exposure landscape:
    12K+ internet-facing instances observed (Shodan)
    File transfer platforms remain ransomware-favored entry vectors

    Historical context:
    Prior Serv-U CVEs exploited by ransomware groups and state-aligned actors.

    Immediate actions:
    - Patch to 15.5.4
    - Audit privileged accounts
    - Review FTP/SFTP exposure
    - Monitor for anomalous admin creation

    Source: bleepingcomputer.com/news/secu

    Follow us for tactical advisories and vulnerability intelligence.

    Comment with your detection or hardening recommendations.

    #Infosec #SolarWinds #ThreatIntel #CVE2025 #RCE #PrivilegeEscalation #BlueTeam #SecurityEngineering #AttackSurface #ZeroTrust

  2. 🚨 CVE-2025-14388: CRITICAL vuln in PhastPress (≤3.7) lets unauth attackers read files like wp-config.php using double-encoded null bytes. Patch unavailable—disable plugin, block %2500 in URLs, monitor logs! radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vulnerability #CVE2025

  3. 🚨 CVE-2025-14388: CRITICAL vuln in PhastPress (≤3.7) lets unauth attackers read files like wp-config.php using double-encoded null bytes. Patch unavailable—disable plugin, block %2500 in URLs, monitor logs! radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vulnerability #CVE2025

  4. 🔎 CVE-2025-11544 (CRITICAL, CVSS 9.5): Sharp Display Solutions projectors let attackers upload unauthorized firmware—remote, no auth needed. All models vulnerable. Urgently segment, restrict, and monitor! radar.offseq.com/threat/cve-20 #OffSeq #CVE2025 #infosec #embeddedsecurity

  5. 🔴 CVE-2025-11545: CRITICAL vuln in all Sharp projectors—embedded HTTP server leaks sensitive info, enables unauth’d remote actions. Network access only! Segment, restrict HTTP, monitor for abuse. Patch ASAP when available. radar.offseq.com/threat/cve-20 #OffSeq #CVE2025 #IoTSecurity

  6. 🚨 CVE-2025-15016: CRITICAL flaw in Ragic Enterprise Cloud Database. Hard-coded crypto key enables remote, unauthenticated access as any user. Audit & restrict access urgently. No patch yet—mitigate now! radar.offseq.com/threat/cve-20 #OffSeq #CloudSecurity #Vulnerability #CVE2025

  7. 🚨 CVE-2025-68398: CRITICAL vuln in Weblate (<5.15.1). Privileged users can overwrite Git configs, risking full system compromise. Patch to 5.15.1+ & audit Git settings now! radar.offseq.com/threat/cve-20 #OffSeq #Weblate #Infosec #CVE2025

  8. 🚨 CVE-2025-68398: CRITICAL vuln in Weblate (<5.15.1). Privileged users can overwrite Git configs, risking full system compromise. Patch to 5.15.1+ & audit Git settings now! radar.offseq.com/threat/cve-20 #OffSeq #Weblate #Infosec #CVE2025

  9. ⚠️ CRITICAL: CVE-2025-47372 impacts Qualcomm Snapdragon (many models). Classic buffer overflow via oversized ELF files causes memory corruption—no auth required. Security teams: review exposure & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Snapdragon #CVE2025

  10. ⚠️ HIGH severity: CVE-2025-11924 impacts Ninja Forms (WordPress), letting unauthenticated attackers access form data via REST API. Patch 3.13.1 is ineffective. Restrict API, audit tokens, and monitor logs. More info: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2025 #Security

  11. 🚨 CRITICAL: CVE-2025-13955 in EZCast Pro II v1.17478.146 — Predictable default Wi-Fi password lets attackers nearby calculate access credentials. Review your AP configs & restrict access. More info: radar.offseq.com/threat/cve-20 #OffSeq #CVE2025 #IoTSecurity #Infosec

  12. Cal.com has patched a critical authentication bypass (CVE-2025-66489) that allowed attackers to submit any non-empty TOTP field and skip password checks. Versions ≤5.9.7 were impacted.

    Update to 5.9.8 to ensure both password and TOTP verification are enforced.
    How should MFA implementations be validated to prevent logic gaps like this?

    Source: gbhackers.com/critical-cal-com

    Share your insights and follow us for more security reporting.

    #infosec #appsec #CVE2025 #authentication #MFA #ThreatIntel #SecureCoding #SoftwareSecurity #VulnerabilityManagement #SecurityUpdate

  13. Cal.com has patched a critical authentication bypass (CVE-2025-66489) that allowed attackers to submit any non-empty TOTP field and skip password checks. Versions ≤5.9.7 were impacted.

    Update to 5.9.8 to ensure both password and TOTP verification are enforced.
    How should MFA implementations be validated to prevent logic gaps like this?

    Source: gbhackers.com/critical-cal-com

    Share your insights and follow us for more security reporting.

    #infosec #appsec #CVE2025 #authentication #MFA #ThreatIntel #SecureCoding #SoftwareSecurity #VulnerabilityManagement #SecurityUpdate

  14. 🛡️ CVE-2025-13646: HIGH severity in wpchill Image Gallery for WordPress (v2.13.1). Authenticated Author+ users can upload dangerous files, risking RCE. Restrict roles, monitor uploads, and patch ASAP. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vuln #CVE2025 #Cybersecurity

  15. ⚠️ CRITICAL: CVE-2025-13658 hits Industrial Video & Control Longwatch v6.309 — remote unauthenticated code execution via HTTP GET grants SYSTEM privileges. No patch yet. Segment, restrict access, monitor traffic. Full advisory: radar.offseq.com/threat/cve-20 #OffSeq #OTSecurity #CVE2025

  16. ASUS has patched a high-severity local privilege escalation flaw (CVE-2025-59373) in MyASUS that allowed elevation to NT AUTHORITY/SYSTEM via the System Control Interface Service. Patch now shipped through Windows Update with updated versions for x64 and ARM.

    Full details:
    technadu.com/asus-fixes-high-s

    #infosec #vulnerability #ASUS #WindowsSecurity #patchmanagement #CVE2025

  17. 🚨 CVE-2025-13597 (CRITICAL): soportecibeles AI Feeds ≤1.0.11 for WordPress allows unauthenticated file uploads via 'actualizador_git.php', enabling RCE. Restrict access & monitor file integrity while awaiting patch. Details: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2025

  18. Threat actors are actively exploiting CVE-2025-59287 in WSUS to deploy ShadowPad.

    ASEC notes the attackers used PowerCat for shell access, then fetched and installed ShadowPad with certutil/curl, executing it through DLL side-loading.

    How are you securing WSUS or other update infrastructure in your environment?
    💬 Share your insights
    ⭐ Follow TechNadu for timely threat intel

    #infosec #WSUS #ShadowPad #CVE2025 #malware #threatintel #sysadmin #DFIR #TechNadu

  19. Threat actors are actively exploiting CVE-2025-59287 in WSUS to deploy ShadowPad.

    ASEC notes the attackers used PowerCat for shell access, then fetched and installed ShadowPad with certutil/curl, executing it through DLL side-loading.

    How are you securing WSUS or other update infrastructure in your environment?
    💬 Share your insights
    ⭐ Follow TechNadu for timely threat intel

    #infosec #WSUS #ShadowPad #CVE2025 #malware #threatintel #sysadmin #DFIR #TechNadu

  20. 🔥 CVE-2025-13551 (HIGH): Buffer overflow in D-Link DIR-822K/DWR-M920 (firmware 1.00_20250513164613, 1.1.50). Remote, unauthenticated RCE possible; public exploit out. Isolate & monitor now! More: radar.offseq.com/threat/cve-20 #OffSeq #DLink #CVE2025 #RouterSecurity

  21. 🚨 CVE-2025-64762 (HIGH): workos authkit-nextjs <2.11.1 fails to set anti-caching headers, risking session token leaks via CDN caches. Upgrade to 2.11.1+ or review CDN cache configs now! radar.offseq.com/threat/cve-20 #OffSeq #Nextjs #Security #CVE2025

  22. 🚨 CRITICAL: CVE-2025-64310 in EPSON WebConfig for Projectors enables unlimited login attempts, risking brute force admin password attacks. Check vendor for affected versions & mitigation steps. radar.offseq.com/threat/cve-20 #OffSeq #CVE2025 #Vuln #InfoSec

  23. 🚨 CVE-2025-13035: HIGH severity PHP code injection in Code Snippets plugin (≤3.9.1) for WordPress. Attackers with Contributor+ access & admin action can run arbitrary code. Disable file-based execution & restrict access. Details: radar.offseq.com/threat/cve-20 #OffSeq #WordPress #CVE2025 #Security

  24. 🛡️ CVE-2025-13258: HIGH severity buffer overflow in Tenda AC20 routers (≤16.03.08.12) via /goform/WifiExtraSet. Public exploit out—remotely exploitable, no auth needed. Restrict access, monitor, and patch ASAP. radar.offseq.com/threat/cve-20 #OffSeq #CVE2025 #Tenda #BufferOverflow

  25. 🚨 CRITICAL: CVE-2025-8489 in King Addons for Elementor (WordPress). All versions let unauth attackers create admin accounts due to improper privilege controls (CWE-269). Disable plugin, monitor registrations, and enforce MFA. radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Infosec #CVE2025

  26. 🔒 CVE-2025-12363 (CRITICAL): Azure Access Tech BLU-IC2/IC4 ≤1.19.5 leaks email passwords (CWE-200). No authentication or patch! Restrict access, enable MFA, audit logs. More: radar.offseq.com/threat/cve-20 #OffSeq #Azure #Vulnerability #CVE2025 #BlueTeam

  27. Threat brief: Operation ZeroDisco — Cisco SNMP zero-day exploited to deploy rootkits
    Summary: CVE-2025-20352 (SNMP stack overflow) is being chained with a modified CVE-2017-3881 Telnet exploit to remotely write memory and deliver a rootkit impacting Cisco 9400/9300/3750G series. Indicators: sudden universal password containing disco, hidden running-config differences, disabled log history, unexpected UDP listeners on closed ports, unexplained VLAN bridging. No reliable automated scanner exists yet - escalate to

    Cisco TAC and initiate low-level firmware/ROM inspection if suspected. Prioritize patching, isolate legacy gear, and monitor SNMP/Telnet telemetry and VLAN changes. Share detections back to the community and follow TechNadu for consolidated IOCs.

    #CVE2025 #ZeroDisco #Cisco #Rootkit #SNMP #VLAN #IoTSecurity #ThreatIntel #PatchManagement #TechNadu

  28. ⚠️ New Critical Linux CVE ⚠️

    Unless you’re using Talos Linux.

    In which case, you're fully secure. Carry on, and let your minimal, immutable OS keep you safe from CVE-2025-32463 and CVE-2025-32462.

    #CVE2025 #Linux #Kubernetes #CyberSecurity

  29. ⚠️ New Critical Linux CVE ⚠️

    Unless you’re using Talos Linux.

    In which case, you're fully secure. Carry on, and let your minimal, immutable OS keep you safe from CVE-2025-32463 and CVE-2025-32462.

    #CVE2025 #Linux #Kubernetes #CyberSecurity

  30. 🔒 CRITICAL: CVE-2025-49794 in libxml2 hits RHEL 10. Remote, unauthenticated use-after-free via crafted XML can crash apps or cause undefined behavior. Monitor for patches, filter XML inputs, and restrict access! radar.offseq.com/threat/cve-20 #OffSeq #Linux #RHEL #CVE2025 #Infosec

  31. 🚨 Chinese hackers exploiting a Cityworks zero-day (CVE-2025-0994) to hit US local agencies, including municipal systems and public services, warns #CiscoTalos.

    Read: hackread.com/chinese-hackers-e

    #CyberSecurity #Infosec #CVE2025 #Cityworks #ZeroDay #RCE #China

  32. 🚨 #CISA warns CVE-2025-3248 in Langflow is being actively exploited. Critical RCE flaw allows full server takeover. Patch to v1.3.0 ASAP.

    #Infosec #CVE2025 #Langflow #CyberSecurity

    Read: hackread.com/langflow-vulnerab