Tag: Critical RCE Vulnerability

Ongoing Attacks Exploiting Critical RCE Vulnerability in Legacy D-Link DSL Routers
News

Ongoing Attacks Exploiting Critical RCE Vulnerability in Legacy D-Link DSL Routers

Legacy D-Link DSL gateway routers have a recently identified major security issue that is being actively exploited in the field. The vulnerability, identified as CVE-2026-0625 (CVSS score: 9.3), relates to a command injection situation in the "dnscfg.cgi" endpoint that results from inadequate sanitization of DNS configuration parameters submitted by the user. According to a VulnCheck advisory, an unauthenticated remote attacker can inject and run arbitrary shell commands, leading to remote code execution. D-Link confirmed active exploitation operations targeting firmware variants of the DSL-2740R, DSL-2640B, DSL-2780B, and DSL-526B models from 2016 to 2019. The impacted endpoint is also linked to unauthenticated DNS alteration ('DNSChanger') behavior. The cybersecurity firm also ...
Veeam Patches Critical RCE Vulnerability with CVSS 9.0 in Backup & Replication
News

Veeam Patches Critical RCE Vulnerability with CVSS 9.0 in Backup & Replication

In order to fix many vulnerabilities in its Backup & Replication software, including a "critical" problem that might lead to remote code execution (RCE), Veeam has released security upgrades. The vulnerability has a CVSS score of 9.0 and is tagged as CVE-2025-59470. According to a Tuesday notice, this vulnerability enables a Backup or Tape Operator to execute remote code execution (RCE) as the Postgres user by passing a malicious interval or order parameter. A user with a Backup Operator role can start and stop running tasks, export backups, copy backups, and make VeeamZip backups, according to Veeam's documentation. In contrast, a user of Tape Operator has the ability to perform tape backup or catalog tasks, eject tapes, import and export tapes, move tapes to a media pool, copy...
Gladinet’s Triofox and CentreStack Under Active Exploitation via Critical RCE Vulnerability
News

Gladinet’s Triofox and CentreStack Under Active Exploitation via Critical RCE Vulnerability

According to Huntress, Gladinet CentreStack's Triofox remote access and collaboration solution is also affected by a previously revealed security issue that has impacted seven other organizations so far. The vulnerability, identified as CVE-2025-30406 (CVSS score: 9.0), concerns the usage of a hard-coded cryptographic key that may allow remote code execution attacks against servers that are accessible over the internet. On April 3, 2025, CenterStack version 16.4.10315.56368 was released, which addressed the issue. The specifics of the assaults are unknown, but it is said that the vulnerability was exploited as a zero-day in March 2025. Huntress now claims that Gladinet Triofox versions up to 16.4.10317.56372 are also impacted by the vulnerability read more about Gladinet's Triofo...
Critical RCE Vulnerability Discovered in Ollama AI Infrastructure Tool
News

Critical RCE Vulnerability Discovered in Ollama AI Infrastructure Tool

Researchers studying cybersecurity have identified a vulnerability that can be leveraged to accomplish remote code execution on the Ollama open-source artificial intelligence (AI) infrastructure platform. This vulnerability is currently fixed. Cloud security company Wiz has given the vulnerability, which is tracked as CVE-2024-37032, the codename Probllama. Version 0.1.34 was released on May 7, 2024, and it resolved the issue after responsible disclosure on May 5, 2024. Large language models (LLMs) can be packaged, deployed, and operated locally on Windows, Linux, and macOS devices using the Ollama service. Basically, the problem is a case of inadequate input validation that causes a path traversal vulnerability that an attacker might use to overwrite any file on the server and e...
Fortra Patches Critical RCE Vulnerability in FileCatalyst Transfer Tool
News

Fortra Patches Critical RCE Vulnerability in FileCatalyst Transfer Tool

Details of a significant security vulnerability that has been fixed in Fortra's FileCatalyst file transfer software have been made public. This vulnerability might give unauthenticated attackers access to remote code execution on vulnerable servers. The vulnerability, identified as CVE-2024-25153, has a CVSS score of 9.8 out of a possible 10. Using a specifically constructed POST request, files can be uploaded outside of the intended 'uploadtemp' directory using a directory traversal within the 'ftpservlet' of the FileCatalyst Workflow Web Portal, the business stated in an alert last week. When a file is successfully uploaded to the DocumentRoot of a web portal, specifically designed JSP files may be used to run programs read more Fortra Patches Critical RCE Vulnerability in File...