[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[FD] batch-2: 15 vulnerabilities incl. multiple pre-auth RCE across 10 enterprise/SCADA products - full analyses + reproducible exploits
- To: fulldisclosure@xxxxxxxxxxxx
- Subject: [FD] batch-2: 15 vulnerabilities incl. multiple pre-auth RCE across 10 enterprise/SCADA products - full analyses + reproducible exploits
- From: disclosure via Fulldisclosure <fulldisclosure@xxxxxxxxxxxx>
- Date: Wed, 5 Aug 2026 09:27:50 +0000
TO: fulldisclosure@xxxxxxxxxxxx
FROM: disclosure@xxxxxxxxxxxxxxxx
SUBJECT: [FD] batch-2: 15 vulnerabilities incl. multiple pre-auth RCE across 10
enterprise/SCADA products - full analyses + reproducible exploits
----BODY----
0day Rubbish Research Team is publishing its second batch of AI-assisted
vulnerability research: 15 vulnerabilities across 10 enterprise, SCADA, and
industrial software products. All findings are publicly disclosed
(synchronous, no embargo); affected vendors were notified in parallel. Each
entry below links to a full technical analysis with a reproducible
proof-of-concept. PoC repository:
https://github.com/Exploit-Garbage/0day-Rubbish
1. AOMEI Cyber Backup v2.3.0 (AOMEI)
- Pre-authentication RCE (CVSS 9.8): unauthenticated root RCE via the
unauthenticated internal Thrift ports (9074/9078) and a NAS-mount command
injection (system() with unescaped username/password). Runs as root in a
Docker container; no credentials or user interaction required.
Advisory:
https://0day-rubbish.com/blog/aomei-cyber-backup-thrift-nas-mount-rce
2. Apache Struts 2 v2.6.11.0
- Pre-authentication RCE: OGNL injection via the RESTful mapper request path,
allowing remote code execution without authentication.
Advisory:
https://0day-rubbish.com/blog/apache-struts2-restful-mapper-ognl-rce
3. atvise SCADA 3.13.0 (atvise GmbH / Bachmann Visutec)
- Pre-authentication root RCE (CVSS 9.8): the OPC UA logonSessionUser path
never verifies the password; any non-empty password for root yields a
superuser session, combined with V8 script injection via an OPC UA write
and an anonymous WebMI trigger. Verified by reading /etc/shadow.
Advisory: https://0day-rubbish.com/blog/atvise-scada-opcua-unauth-rce
- Default-credential RCE (CVSS 8.8): factory-default empty root password plus
a 'password not set' branch that grants the superuser session; V8 injection
via AddNode and a ReportRunConfiguration trigger.
Advisory: https://0day-rubbish.com/blog/atvise-scada-webmi-auth-rce
4. CatDV Server 10.7.8 (Square Box Systems)
- Authenticated RCE: aaftoolPath command injection executing as root.
Advisory: https://0day-rubbish.com/blog/catdv-server-aaftoolPath-root-rce
- Hardcoded credentials: admin factory-default empty password.
Advisory:
https://0day-rubbish.com/blog/catdv-server-admin-factory-default-empty-password
- Pre-authentication RCE: unauthenticated RMI path leading to root RCE.
Advisory: https://0day-rubbish.com/blog/catdv-server-unauth-rmi-root-rce
5. CIRCUTOR PowerStudio SCADA WAVE 24.11.6.0 (CIRCUTOR)
- Authentication bypass: a fail-open shared JWT library accepting alg=none
tokens, enabling identity forgery.
Advisory:
https://0day-rubbish.com/blog/circutor-powerstudio-jwt-alg-none-identity-forgery
- Pre-authentication SYSTEM RCE: JWT forgery combined with a shellExecute
event action yielding SYSTEM-level code execution.
Advisory:
https://0day-rubbish.com/blog/circutor-powerstudio-unauth-shellExecute-rce
6. Stimulsoft Server 2026.3.1 (Stimulsoft)
- Pre-authentication SYSTEM RCE: unauthenticated report-script injection.
Advisory:
https://0day-rubbish.com/blog/stimulsoft-server-unauth-report-script-rce
7. Plastic SCM (Unity Technologies)
- Pre-authentication RCE: unauthenticated RCE on port 8087.
Advisory: https://0day-rubbish.com/blog/plastic-scm-unauth-8087-rce
8. Vicon Valerus / ViconNet Gateway (Vicon)
- Pre-authentication SYSTEM RCE: unauthenticated command injection.
Advisory:
https://0day-rubbish.com/blog/vicon-valerus-unauth-cmd-injection-rce
9. vMix 29 v29.0.0.48 (vMix)
- Pre-authentication RCE: VBScript blocklist bypass.
Advisory: https://0day-rubbish.com/blog/vmix-vbscript-blocklist-bypass-rce
10. Xeams 10.3 build 6449 (Synametrics)
- Pre-authentication RCE: SMTP saveBody cron-job injection.
Advisory: https://0day-rubbish.com/blog/xeams-smtp-savebody-cron-rce
- Pre-authentication RCE: unauthenticated SQL-runner Derby JSP injection.
Advisory:
https://0day-rubbish.com/blog/xeams-unauth-sqlrunner-derby-jsp-rce
Proof-of-concept scripts and full technical analyses are available at the
advisory URLs above and at https://github.com/Exploit-Garbage/0day-Rubbish
Disclosure stance: synchronous (no embargo). Vendors were notified in parallel
with publication. We are open to coordination with vendors, CISA, or other
coordinators who wish to publish advisories.
--
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/