[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[FD] batch-2: 15 vulnerabilities incl. multiple pre-auth RCE across 10 enterprise/SCADA products - full analyses + reproducible exploits



TO: fulldisclosure@xxxxxxxxxxxx
FROM: disclosure@xxxxxxxxxxxxxxxx
SUBJECT: [FD] batch-2: 15 vulnerabilities incl. multiple pre-auth RCE across 10 
enterprise/SCADA products - full analyses + reproducible exploits
----BODY----
0day Rubbish Research Team is publishing its second batch of AI-assisted
vulnerability research: 15 vulnerabilities across 10 enterprise, SCADA, and
industrial software products. All findings are publicly disclosed
(synchronous, no embargo); affected vendors were notified in parallel. Each
entry below links to a full technical analysis with a reproducible
proof-of-concept. PoC repository: 
https://github.com/Exploit-Garbage/0day-Rubbish

1. AOMEI Cyber Backup v2.3.0 (AOMEI)
   - Pre-authentication RCE (CVSS 9.8): unauthenticated root RCE via the
     unauthenticated internal Thrift ports (9074/9078) and a NAS-mount command
     injection (system() with unescaped username/password). Runs as root in a
     Docker container; no credentials or user interaction required.
     Advisory: 
https://0day-rubbish.com/blog/aomei-cyber-backup-thrift-nas-mount-rce

2. Apache Struts 2 v2.6.11.0
   - Pre-authentication RCE: OGNL injection via the RESTful mapper request path,
     allowing remote code execution without authentication.
     Advisory: 
https://0day-rubbish.com/blog/apache-struts2-restful-mapper-ognl-rce

3. atvise SCADA 3.13.0 (atvise GmbH / Bachmann Visutec)
   - Pre-authentication root RCE (CVSS 9.8): the OPC UA logonSessionUser path
     never verifies the password; any non-empty password for root yields a
     superuser session, combined with V8 script injection via an OPC UA write
     and an anonymous WebMI trigger. Verified by reading /etc/shadow.
     Advisory: https://0day-rubbish.com/blog/atvise-scada-opcua-unauth-rce
   - Default-credential RCE (CVSS 8.8): factory-default empty root password plus
     a 'password not set' branch that grants the superuser session; V8 injection
     via AddNode and a ReportRunConfiguration trigger.
     Advisory: https://0day-rubbish.com/blog/atvise-scada-webmi-auth-rce

4. CatDV Server 10.7.8 (Square Box Systems)
   - Authenticated RCE: aaftoolPath command injection executing as root.
     Advisory: https://0day-rubbish.com/blog/catdv-server-aaftoolPath-root-rce
   - Hardcoded credentials: admin factory-default empty password.
     Advisory: 
https://0day-rubbish.com/blog/catdv-server-admin-factory-default-empty-password
   - Pre-authentication RCE: unauthenticated RMI path leading to root RCE.
     Advisory: https://0day-rubbish.com/blog/catdv-server-unauth-rmi-root-rce

5. CIRCUTOR PowerStudio SCADA WAVE 24.11.6.0 (CIRCUTOR)
   - Authentication bypass: a fail-open shared JWT library accepting alg=none
     tokens, enabling identity forgery.
     Advisory: 
https://0day-rubbish.com/blog/circutor-powerstudio-jwt-alg-none-identity-forgery
   - Pre-authentication SYSTEM RCE: JWT forgery combined with a shellExecute
     event action yielding SYSTEM-level code execution.
     Advisory: 
https://0day-rubbish.com/blog/circutor-powerstudio-unauth-shellExecute-rce

6. Stimulsoft Server 2026.3.1 (Stimulsoft)
   - Pre-authentication SYSTEM RCE: unauthenticated report-script injection.
     Advisory: 
https://0day-rubbish.com/blog/stimulsoft-server-unauth-report-script-rce

7. Plastic SCM (Unity Technologies)
   - Pre-authentication RCE: unauthenticated RCE on port 8087.
     Advisory: https://0day-rubbish.com/blog/plastic-scm-unauth-8087-rce

8. Vicon Valerus / ViconNet Gateway (Vicon)
   - Pre-authentication SYSTEM RCE: unauthenticated command injection.
     Advisory: 
https://0day-rubbish.com/blog/vicon-valerus-unauth-cmd-injection-rce

9. vMix 29 v29.0.0.48 (vMix)
   - Pre-authentication RCE: VBScript blocklist bypass.
     Advisory: https://0day-rubbish.com/blog/vmix-vbscript-blocklist-bypass-rce

10. Xeams 10.3 build 6449 (Synametrics)
    - Pre-authentication RCE: SMTP saveBody cron-job injection.
      Advisory: https://0day-rubbish.com/blog/xeams-smtp-savebody-cron-rce
    - Pre-authentication RCE: unauthenticated SQL-runner Derby JSP injection.
      Advisory: 
https://0day-rubbish.com/blog/xeams-unauth-sqlrunner-derby-jsp-rce

Proof-of-concept scripts and full technical analyses are available at the
advisory URLs above and at https://github.com/Exploit-Garbage/0day-Rubbish

Disclosure stance: synchronous (no embargo). Vendors were notified in parallel
with publication. We are open to coordination with vendors, CISA, or other
coordinators who wish to publish advisories.

--
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/