<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>network — PoC Archive</title><link>https://poc.intelseclab.com/pocs/network/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 16 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/pocs/network/index.xml" rel="self" type="application/rss+xml"/><item><title>UniFi OS -- Unauthenticated Command Injection RCE (CVE-2026-34910)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-34910-unifi-os-unauth-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-34910-unifi-os-unauth-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-34910, CVE-2026-34909, CVE-2026-34908. Status: Patched. Affects: Ubiquiti UniFi OS Server. Tags: ubiquiti, unifi, unifi-os, auth-bypass, path-traversal, command-injection, rce, unauth, kev, mirai, nginx, CVE-2026-34910.</description><category>network</category><category>Critical</category><category>ubiquiti</category><category>unifi</category><category>unifi-os</category><category>auth-bypass</category><category>path-traversal</category><category>command-injection</category><category>rce</category><category>unauth</category><category>kev</category><category>mirai</category><category>nginx</category><category>CVE-2026-34910</category></item><item><title>Citrix NetScaler ADC/Gateway -- Pre-Auth SAML PrefixList Heap Overflow to RCE (CVE-2026-8452)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-8452-citrix-netscaler-saml-preauth-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-8452-citrix-netscaler-saml-preauth-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-8452. Status: Patched. Affects: Citrix NetScaler ADC and NetScaler Gateway. Tags: citrix, netscaler, adc, gateway, saml, heap-overflow, preauth, rce, shellcode, webshell, freebsd, xml-signature, c14n, CVE-2026-8452.</description><category>network</category><category>Critical</category><category>citrix</category><category>netscaler</category><category>adc</category><category>gateway</category><category>saml</category><category>heap-overflow</category><category>preauth</category><category>rce</category><category>shellcode</category><category>webshell</category><category>freebsd</category><category>xml-signature</category><category>c14n</category><category>CVE-2026-8452</category></item><item><title>Cisco IMC Argument Injection to Root RCE (CVE-2026-20200)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-20200-cisco-imc-argument-injection-rce/</link><pubDate>Sun, 16 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-16_cve-2026-20200-cisco-imc-argument-injection-rce/</guid><description>Critical severity (CVSS 9.9) — network · CVE-2026-20200 / NSIDE-SA-2026-003. Status: Patched. Affects: Cisco Integrated Management Controller (CIMC). Tags: cisco, imc, cimc, argument-injection, rce, redfish, curl, reverse-shell, arm, file-read, file-write, CVE-2026-20200.</description><category>network</category><category>Critical</category><category>cisco</category><category>imc</category><category>cimc</category><category>argument-injection</category><category>rce</category><category>redfish</category><category>curl</category><category>reverse-shell</category><category>arm</category><category>file-read</category><category>file-write</category><category>CVE-2026-20200</category></item><item><title>Microsoft SCCM — AdminService CAB Extraction Path-Traversal to SYSTEM RCE (CVE-2026-47301)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-15_cve-2026-47301-sccm-adminservice-cab-rce/</link><pubDate>Sat, 15 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-15_cve-2026-47301-sccm-adminservice-cab-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-47301. Status: Patched. Affects: Microsoft Configuration Manager (SCCM / ConfigMgr), AdminService REST API. Tags: windows, sccm, configmgr, rce, cab, path-traversal, dll-hijacking, dll-proxy, arbitrary-file-write, system, microsoft, CVE-2026-47301.</description><category>network</category><category>Critical</category><category>windows</category><category>sccm</category><category>configmgr</category><category>rce</category><category>cab</category><category>path-traversal</category><category>dll-hijacking</category><category>dll-proxy</category><category>arbitrary-file-write</category><category>system</category><category>microsoft</category><category>CVE-2026-47301</category></item><item><title>Windows Kerberos — ResetNightmare: Arbitrary Password Reset via Change Password Protocol Validation Flaw (CVE-2026-27912)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-11_cve-2026-27912-resetnightmare-kerberos-changepw-password-reset/</link><pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-11_cve-2026-27912-resetnightmare-kerberos-changepw-password-reset/</guid><description>High severity (CVSS 8) — network · CVE-2026-27912. Status: Patched. Affects: Microsoft Windows Kerberos Key Distribution Center (KDC), Change Password protocol (kadmin/changepw). Tags: windows, kerberos, active-directory, privilege-escalation, password-reset, domain-controller, upn, rubeus, changepw, krbtgt, CWE-285, microsoft, CVE-2026-27912.</description><category>network</category><category>High</category><category>windows</category><category>kerberos</category><category>active-directory</category><category>privilege-escalation</category><category>password-reset</category><category>domain-controller</category><category>upn</category><category>rubeus</category><category>changepw</category><category>krbtgt</category><category>CWE-285</category><category>microsoft</category><category>CVE-2026-27912</category></item><item><title>Active Directory — SPN Unicode Collision Detection Scanner (CVE-2026-25177)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-11_cve-2026-25177-ad-spn-unicode-collision-detector/</link><pubDate>Tue, 11 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-11_cve-2026-25177-ad-spn-unicode-collision-detector/</guid><description>High severity (CVSS 8.8) — network · CVE-2026-25177. Status: Patched. Affects: Microsoft Active Directory Domain Services, Service Principal Name (SPN) validation. Tags: windows, active-directory, kerberos, spn, unicode, homoglyph, privilege-escalation, detection, scanner, ldap, CWE-641, microsoft, CVE-2026-25177.</description><category>network</category><category>High</category><category>windows</category><category>active-directory</category><category>kerberos</category><category>spn</category><category>unicode</category><category>homoglyph</category><category>privilege-escalation</category><category>detection</category><category>scanner</category><category>ldap</category><category>CWE-641</category><category>microsoft</category><category>CVE-2026-25177</category></item><item><title>Ivanti Endpoint Manager Mobile (EPMM) Unauthenticated Remote API Access (CVE-2023-35078)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2023-35078-ivanti-epmm-unauth-api-access/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2023-35078-ivanti-epmm-unauth-api-access/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2023-35078 (Ivanti advisory; CWE-287 per NVD). Status: Patched (Ivanti EPMM 11.8.1.1, 11.9.1.1, 11.10.0.2 and later). Affects: Ivanti Endpoint Manager Mobile (EPMM), previously branded MobileIron Core — the /mifs/aad/api/ administrative API surface. Tags: ivanti, epmm, mobileiron-core, mdm, authentication-bypass, cwe-287, unauthenticated, api, pii-disclosure, cisa-kev, ransomware, scanner.</description><category>network</category><category>Critical</category><category>ivanti</category><category>epmm</category><category>mobileiron-core</category><category>mdm</category><category>authentication-bypass</category><category>cwe-287</category><category>unauthenticated</category><category>api</category><category>pii-disclosure</category><category>cisa-kev</category><category>ransomware</category><category>scanner</category></item><item><title>Ivanti Connect Secure / Policy Secure / ZTA Gateways Remote Unauthenticated Stack-Based Buffer Overflow (CVE-2025-22457)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2025-22457-ivanti-connect-secure-stack-overflow/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2025-22457-ivanti-connect-secure-stack-overflow/</guid><description>Critical severity (CVSS 9) — network · CVE-2025-22457. Status: Patched. Affects: Ivanti Connect Secure, Pulse Connect Secure (end of support), Ivanti Policy Secure, Ivanti ZTA Gateways — the /home/bin/web HTTPS front-end process. Tags: ivanti, connect-secure, pulse-connect-secure, policy-secure, zta-gateway, vpn, stack-overflow, CWE-121, buffer-overflow, rce, unauthenticated, rop, heap-spray, aslr-bruteforce, x-forwarded-for, cisa-kev, ransomware, ruby, edge-device.</description><category>network</category><category>Critical</category><category>ivanti</category><category>connect-secure</category><category>pulse-connect-secure</category><category>policy-secure</category><category>zta-gateway</category><category>vpn</category><category>stack-overflow</category><category>CWE-121</category><category>buffer-overflow</category><category>rce</category><category>unauthenticated</category><category>rop</category><category>heap-spray</category><category>aslr-bruteforce</category><category>x-forwarded-for</category><category>cisa-kev</category><category>ransomware</category><category>ruby</category><category>edge-device</category></item><item><title>Check Point Security Management / Multi-Domain Server SmartConsole Authentication Bypass via Forged Application Certificate Bind (CVE-2026-16232)</title><link>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2026-16232-checkpoint-smartconsole-auth-bypass/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-08-09_cve-2026-16232-checkpoint-smartconsole-auth-bypass/</guid><description>Critical severity (CVSS 9.1) — network · CVE-2026-16232. Status: Patched. Affects: Check Point Security Management Server and Multi-Domain Security Management Server (MDS) — the legacy FWM/CPMI SIC service on TCP 18190 and the CPM SOAP web services on TCP 19009. Tags: check-point, smartconsole, security-management-server, multi-domain-server, cpmi, sic, fwm, authentication-bypass, CWE-287, improper-authentication, privilege-escalation, sso-token-forgery, soap, dle, cisa-kev, bod-26-04, python, firewall-management.</description><category>network</category><category>Critical</category><category>check-point</category><category>smartconsole</category><category>security-management-server</category><category>multi-domain-server</category><category>cpmi</category><category>sic</category><category>fwm</category><category>authentication-bypass</category><category>CWE-287</category><category>improper-authentication</category><category>privilege-escalation</category><category>sso-token-forgery</category><category>soap</category><category>dle</category><category>cisa-kev</category><category>bod-26-04</category><category>python</category><category>firewall-management</category></item><item><title>CVE-2022-40684 — FortiOS / FortiProxy / FortiSwitchManager Authentication Bypass (vamp-forticheck Scanner)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-31_cve-2022-40684-fortios-auth-bypass-scanner/</link><pubDate>Fri, 31 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-31_cve-2022-40684-fortios-auth-bypass-scanner/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2022-40684. Status: Patched (FortiOS ≥7.2.2, ≥7.0.7; FortiProxy ≥7.2.1, ≥7.0.7; FortiSwitchManager ≥7.2.1). Affects: Fortinet FortiOS (FortiGate firewalls), FortiProxy web proxy, FortiSwitchManager web management interface / administrative REST API. Tags: fortios, fortiproxy, fortiswitchmanager, authentication-bypass, rest-api, header-injection, loopback-spoofing, fortigate, ssl-vpn, scanner.</description><category>network</category><category>Critical</category><category>fortios</category><category>fortiproxy</category><category>fortiswitchmanager</category><category>authentication-bypass</category><category>rest-api</category><category>header-injection</category><category>loopback-spoofing</category><category>fortigate</category><category>ssl-vpn</category><category>scanner</category></item><item><title>Windows Message Queuing (MSMQ) Queue Manager Heap-Based Buffer Overflow (CVE-2026-54992)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-27_cve-2026-54992-windows-msmq-heap-overflow/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-27_cve-2026-54992-windows-msmq-heap-overflow/</guid><description>High severity (CVSS 8.4) — network · CVE-2026-54992. Status: PoC (crash/DoS confirmed, no RCE demonstrated). Affects: Windows Message Queuing (MSMQ) — Queue Manager (mqqm.dll, hosted in mqsvc.exe), reached via the MS-MQRR (RemoteRead) RPC interface. Tags: windows, msmq, message-queuing, heap-overflow, integer-overflow, rpc, dos, crash.</description><category>network</category><category>High</category><category>windows</category><category>msmq</category><category>message-queuing</category><category>heap-overflow</category><category>integer-overflow</category><category>rpc</category><category>dos</category><category>crash</category></item><item><title>AD CS/AD FS Enrollment "cdc" Chase Attribute Abuse → Domain Controller Impersonation (CertiGhost, CVE-2026-54121)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-27_cve-2026-54121-certighost-adcs-dc-impersonation/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-27_cve-2026-54121-certighost-adcs-dc-impersonation/</guid><description>High severity (CVSS 8.8) — network · CVE-2026-54121. Status: Weaponized. Affects: Microsoft Active Directory Certificate Services (AD CS) Enterprise CA, in environments where AD FS / certificate enrollment resolves DC identity via "chase" (cdc/rmd) request attributes. Tags: active-directory, adcs, certificate-services, dcsync, pkinit, kerberos, privilege-escalation, domain-controller-impersonation, windows.</description><category>network</category><category>High</category><category>active-directory</category><category>adcs</category><category>certificate-services</category><category>dcsync</category><category>pkinit</category><category>kerberos</category><category>privilege-escalation</category><category>domain-controller-impersonation</category><category>windows</category></item><item><title>Cisco Unified Communications Manager WebDialer SSRF → Arbitrary File Write → Root (CVE-2026-20230)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-19_cve-2026-20230-cisco-ucm-ssrf-arbitrary-file-write/</link><pubDate>Sun, 19 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-19_cve-2026-20230-cisco-ucm-ssrf-arbitrary-file-write/</guid><description>Critical severity (CVSS 8.6) — network · CVE-2026-20230 (cisco-sa-cucm-ssrf-cXPnHcW). Status: PoC — scanner/tester confirms the WebDialer precondition and SSRF reachability. Affects: Cisco Unified Communications Manager (Unified CM) and Unified CM Session Management Edition (SME) — WebDialer service. Tags: cisco, unified-communications-manager, ucm, webdialer, ssrf, cwe-918, unauthenticated, remote, privilege-escalation, kev, actively-exploited.</description><category>network</category><category>Critical</category><category>cisco</category><category>unified-communications-manager</category><category>ucm</category><category>webdialer</category><category>ssrf</category><category>cwe-918</category><category>unauthenticated</category><category>remote</category><category>privilege-escalation</category><category>kev</category><category>actively-exploited</category></item><item><title>SonicWall SMA1000 WorkPlace SSRF → Internal Erlang RPC Remote Code Execution (CVE-2026-15409)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-15_cve-2026-15409-sonicwall-sma1000-ssrf-erlang-rce/</link><pubDate>Wed, 15 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-15_cve-2026-15409-sonicwall-sma1000-ssrf-erlang-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2026-15409 (SNWLID-2026-0008). Status: Weaponized — unauthenticated, non-root remote code execution confirmed against a real appliance build. Affects: SonicWall SMA1000 Appliance — WorkPlace interface (websocket proxy service). Tags: sonicwall, sma1000, workplace, ssrf, erlang, rpc, cwe-918, unauthenticated, remote, kev, actively-exploited.</description><category>network</category><category>Critical</category><category>sonicwall</category><category>sma1000</category><category>workplace</category><category>ssrf</category><category>erlang</category><category>rpc</category><category>cwe-918</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>actively-exploited</category></item><item><title>OpenSSH Forwarded-Agent Lock/Unlock State Confusion → Unauthorized PKCS#11 Provider Load (No CVE)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-12_openssh-agent-lock-provider-bypass/</link><pubDate>Sun, 12 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-12_openssh-agent-lock-provider-bypass/</guid><description>High severity — network. Status: PoC — reproducible against a signed, checksum/signature-verified stock OpenSSH 10.4p1 build; no weaponized payload beyond starting an allowed PKCS#11 provider. Affects: OpenSSH portable — ssh, sshd, ssh-agent. Tags: openssh, ssh-agent, agent-forwarding, pkcs11, race-condition, state-confusion, no-cve, local-provider-abuse.</description><category>network</category><category>High</category><category>openssh</category><category>ssh-agent</category><category>agent-forwarding</category><category>pkcs11</category><category>race-condition</category><category>state-confusion</category><category>no-cve</category><category>local-provider-abuse</category></item><item><title>D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-11_cve-2022-26258-dlink-dir820l-command-injection/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-11_cve-2022-26258-dlink-dir820l-command-injection/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2022-26258. Status: Weaponized (public PoC available; listed in CISA KEV). Affects: D-Link DIR-820L wireless router, all hardware revisions. Tags: d-link, dir-820l, router, command-injection, cwe-78, unauthenticated, remote, iot, eol-device, kev.</description><category>network</category><category>Critical</category><category>d-link</category><category>dir-820l</category><category>router</category><category>command-injection</category><category>cwe-78</category><category>unauthenticated</category><category>remote</category><category>iot</category><category>eol-device</category><category>kev</category></item><item><title>XRING — XQUIC QPACK Ring Buffer Resize Underflow (Remote Unauthenticated DoS)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-08_xring-xquic-qpack-ring-mem-resize-underflow/</link><pubDate>Wed, 08 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-08_xring-xquic-qpack-ring-mem-resize-underflow/</guid><description>Critical severity — network. Status: Weaponized (public PoC, unpatched at publication). Affects: [alibaba/xquic](https://github.com/alibaba/xquic) — QUIC/HTTP-3 library, used by Tengine and reportedly across Alibaba's cloud/CDN infrastructure (Taobao, AliPay). Tags: quic, http3, qpack, xquic, alibaba, tengine, ring-buffer, integer-underflow, heap-oob-read, memcpy, remote, unauthenticated, dos, no-cve.</description><category>network</category><category>Critical</category><category>quic</category><category>http3</category><category>qpack</category><category>xquic</category><category>alibaba</category><category>tengine</category><category>ring-buffer</category><category>integer-underflow</category><category>heap-oob-read</category><category>memcpy</category><category>remote</category><category>unauthenticated</category><category>dos</category><category>no-cve</category></item><item><title>XSpeeder SXZOS Pre-Auth eval() Remote Code Execution (CVE-2025-54322)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-54322-xspeeder-sxzos-preauth-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-54322-xspeeder-sxzos-preauth-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2025-54322. Status: Weaponized. Affects: XSpeeder SXZOS firmware (SD-WAN devices, routers, edge networking equipment). Tags: xspeeder, sxzos, sd-wan, router, firmware, python, django, eval-injection, pre-auth, rce, cwe-95.</description><category>network</category><category>Critical</category><category>xspeeder</category><category>sxzos</category><category>sd-wan</category><category>router</category><category>firmware</category><category>python</category><category>django</category><category>eval-injection</category><category>pre-auth</category><category>rce</category><category>cwe-95</category></item><item><title>Twonky Server 8.5.2 Unauthenticated `/nmc/rpc/` Auth Bypass &amp; Admin Credential Log Leak (CVE-2025-13315)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-13315-twonky-server-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-13315-twonky-server-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-13315. Status: PoC. Affects: Twonky Server (Lynx Technology), a DLNA/UPnP media server. Tags: twonky-server, dlna, upnp, media-server, auth-bypass, access-control, information-disclosure, credential-leak, cwe-284, unauthenticated, nuclei.</description><category>network</category><category>Critical</category><category>twonky-server</category><category>dlna</category><category>upnp</category><category>media-server</category><category>auth-bypass</category><category>access-control</category><category>information-disclosure</category><category>credential-leak</category><category>cwe-284</category><category>unauthenticated</category><category>nuclei</category></item><item><title>Tenda AC9 `AdvSetMacMtuWan` Stack-Based Buffer Overflow (CVE-2025-29384)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-29384-tenda-ac9-stack-overflow/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-29384-tenda-ac9-stack-overflow/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-29384. Status: PoC. Affects: Tenda AC9 dual-band wireless router, web management interface (/goform/AdvSetMacMtuWan endpoint). Tags: tenda, ac9, router, stack-buffer-overflow, cwe-121, dos, rce, mips, embedded, iot, python, ruby, metasploit.</description><category>network</category><category>Critical</category><category>tenda</category><category>ac9</category><category>router</category><category>stack-buffer-overflow</category><category>cwe-121</category><category>dos</category><category>rce</category><category>mips</category><category>embedded</category><category>iot</category><category>python</category><category>ruby</category><category>metasploit</category></item><item><title>Squid Proxy Sensitive Header Leak via Error Page `mailto:` Diagnostic Block (CVE-2025-62168)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-62168-squid-error-page-header-reflection-token-leak/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-62168-squid-error-page-header-reflection-token-leak/</guid><description>Critical severity (CVSS 10) — network · CVE-2025-62168. Status: PoC. Affects: Squid Proxy. Tags: squid, proxy, information-disclosure, header-reflection, jwt, token-leak, error-page, cwe-209, cwe-550.</description><category>network</category><category>Critical</category><category>squid</category><category>proxy</category><category>information-disclosure</category><category>header-reflection</category><category>jwt</category><category>token-leak</category><category>error-page</category><category>cwe-209</category><category>cwe-550</category></item><item><title>React Native Community CLI Metro Dev Server `/open-url` OS Command Injection (CVE-2025-11953)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-11953-react-native-metro-command-injection/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-11953-react-native-metro-command-injection/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-11953. Status: Weaponized. Affects: @react-native-community/cli / @react-native-community/cli-server-api (Metro Development Server, openURLMiddleware). Tags: react-native, metro, dev-server, cli-server-api, open-url, command-injection, cwe-78, unauthenticated, node.js, python, windows, cross-platform.</description><category>network</category><category>Critical</category><category>react-native</category><category>metro</category><category>dev-server</category><category>cli-server-api</category><category>open-url</category><category>command-injection</category><category>cwe-78</category><category>unauthenticated</category><category>node.js</category><category>python</category><category>windows</category><category>cross-platform</category></item><item><title>Monsta FTP Pre-Authentication Remote Code Execution via Arbitrary File Upload (CVE-2025-34299)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-34299-monsta-ftp-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-34299-monsta-ftp-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-34299. Status: Weaponized. Affects: Monsta FTP (web-based FTP manager). Tags: monsta-ftp, rce, pre-auth, unrestricted-file-upload, cwe-434, php, ftp, docker, nuclei, kev.</description><category>network</category><category>Critical</category><category>monsta-ftp</category><category>rce</category><category>pre-auth</category><category>unrestricted-file-upload</category><category>cwe-434</category><category>php</category><category>ftp</category><category>docker</category><category>nuclei</category><category>kev</category></item><item><title>Mitel MiCollab Path Normalization Bypass to Internal Endpoints (CVE-2025-52913)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-52913-mitel-micollab-path-traversal/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-52913-mitel-micollab-path-traversal/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-52913. Status: PoC. Affects: Mitel MiCollab (unified communications appliance). Tags: mitel, micollab, path-traversal, path-normalization, access-control-bypass, authentication-bypass, cwe-22, axis2, python, unified-communications.</description><category>network</category><category>Critical</category><category>mitel</category><category>micollab</category><category>path-traversal</category><category>path-normalization</category><category>access-control-bypass</category><category>authentication-bypass</category><category>cwe-22</category><category>axis2</category><category>python</category><category>unified-communications</category></item><item><title>HPE OneView `id-pools/executeCommand` OS Command Injection (CVE-2025-37164)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-37164-hpe-oneview-command-injection/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-37164-hpe-oneview-command-injection/</guid><description>Critical severity (CVSS 10) — network · CVE-2025-37164. Status: PoC. Affects: HPE OneView (infrastructure management appliance) REST API. Tags: hpe-oneview, command-injection, os-command-execution, rce, rest-api, python, cwe-78.</description><category>network</category><category>Critical</category><category>hpe-oneview</category><category>command-injection</category><category>os-command-execution</category><category>rce</category><category>rest-api</category><category>python</category><category>cwe-78</category></item><item><title>FreePBX Framework Module Authentication Bypass via Forged Authorization Header (CVE-2025-66039)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-66039-freepbx-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-66039-freepbx-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-66039. Status: PoC. Affects: FreePBX (Sangoma) framework module — web-based administration panel for Asterisk-based VoIP/PBX systems. Tags: freepbx, sangoma, voip, telephony, authentication-bypass, access-control, authtype, webserver-auth, cwe-287, cwe-863, nuclei, version-fingerprinting.</description><category>network</category><category>Critical</category><category>freepbx</category><category>sangoma</category><category>voip</category><category>telephony</category><category>authentication-bypass</category><category>access-control</category><category>authtype</category><category>webserver-auth</category><category>cwe-287</category><category>cwe-863</category><category>nuclei</category><category>version-fingerprinting</category></item><item><title>FortiWeb `cgi-bin/fwbcgi` Path Traversal Authentication Bypass Leading to Rogue Admin Creation (CVE-2025-64446)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-64446-fortiweb-cgiinfo-auth-bypass/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-64446-fortiweb-cgiinfo-auth-bypass/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-64446. Status: PoC. Affects: Fortinet FortiWeb (Web Application Firewall appliance). Tags: fortiweb, fortinet, waf, authentication-bypass, path-traversal, cgiinfo, cwe-22, cwe-288, admin-account-creation, python.</description><category>network</category><category>Critical</category><category>fortiweb</category><category>fortinet</category><category>waf</category><category>authentication-bypass</category><category>path-traversal</category><category>cgiinfo</category><category>cwe-22</category><category>cwe-288</category><category>admin-account-creation</category><category>python</category></item><item><title>FortiOS/FortiProxy/FortiSwitchManager/FortiWeb FortiCloud SSO Authentication Bypass Detection Tool (CVE-2025-59718)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-59718-fortios-version-detection-scanner/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-59718-fortios-version-detection-scanner/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-59718 (Fortinet advisory FG-IR-25-647; related: CVE-2025-59719). Status: PoC. Affects: Fortinet FortiOS, FortiProxy, FortiSwitchManager, FortiWeb. Tags: fortinet, fortios, fortiproxy, fortiswitchmanager, fortiweb, forticloud-sso, authentication-bypass, version-detection, ssh, scanner, cwe-347.</description><category>network</category><category>Critical</category><category>fortinet</category><category>fortios</category><category>fortiproxy</category><category>fortiswitchmanager</category><category>fortiweb</category><category>forticloud-sso</category><category>authentication-bypass</category><category>version-detection</category><category>ssh</category><category>scanner</category><category>cwe-347</category></item><item><title>FiberHome HG6145F1 Predictable Default Wi-Fi PSK Derived from Broadcast SSID (CVE-2025-63353)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-63353-fiberhome-predictable-wifi-psk/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-63353-fiberhome-predictable-wifi-psk/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-63353 / GHSA-cg2x-c25f-6327. Status: PoC. Affects: FiberHome HG6145F1 GPON ONT (Wuhan FiberHome International Technologies). Tags: fiberhome, hg6145f1, gpon-ont, predictable-psk, default-credentials, wpa2, wifi, cwe-284, cwe-1392.</description><category>network</category><category>Critical</category><category>fiberhome</category><category>hg6145f1</category><category>gpon-ont</category><category>predictable-psk</category><category>default-credentials</category><category>wpa2</category><category>wifi</category><category>cwe-284</category><category>cwe-1392</category></item><item><title>D-Link AX1500 SetDeviceSettings `DeviceName` OS Command Injection (CVE-2025-60854)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-60854-dlink-ax1500-devicename-command-injection/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-60854-dlink-ax1500-devicename-command-injection/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-60854. Status: Weaponized. Affects: D-Link AX1500 router firmware (HNAP/DHMAPI web management SOAP interface). Tags: d-link, ax1500, router, command-injection, os-command-injection, hnap, soap, telnetd, cwe-78, iot.</description><category>network</category><category>Critical</category><category>d-link</category><category>ax1500</category><category>router</category><category>command-injection</category><category>os-command-injection</category><category>hnap</category><category>soap</category><category>telnetd</category><category>cwe-78</category><category>iot</category></item><item><title>ConnectWise Automate Adversary-in-the-Middle Remote Code Execution (CVE-2025-11492)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-11492-connectwise-automate-aitm-rce/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-11492-connectwise-automate-aitm-rce/</guid><description>Critical severity (CVSS 9.6) — network · CVE-2025-11492. Status: Weaponized. Affects: ConnectWise Automate (LabTech) RMM Agent. Tags: connectwise-automate, labtech, rmm, aitm, mitm, plugin-hijack, unencrypted-http, des3, privilege-escalation, python, csharp, dnspy, dotnet.</description><category>network</category><category>Critical</category><category>connectwise-automate</category><category>labtech</category><category>rmm</category><category>aitm</category><category>mitm</category><category>plugin-hijack</category><category>unencrypted-http</category><category>des3</category><category>privilege-escalation</category><category>python</category><category>csharp</category><category>dnspy</category><category>dotnet</category></item><item><title>Cisco AsyncOS Spam Quarantine (TCP/6025) Exposure &amp; IOC Scanner (CVE-2025-20393)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-20393-cisco-asyncos-quarantine-rce-scanner/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-20393-cisco-asyncos-quarantine-rce-scanner/</guid><description>Critical severity (CVSS 10) — network · CVE-2025-20393. Status: PoC. Affects: Cisco AsyncOS for Secure Email Gateway (ESA) / Security Management Appliance (SMA). Tags: cisco, asyncos, secure-email-gateway, sma, spam-quarantine, tcp-6025, unauthenticated-rce, exposure-scanner, ioc-detection, backdoor-detection, python.</description><category>network</category><category>Critical</category><category>cisco</category><category>asyncos</category><category>secure-email-gateway</category><category>sma</category><category>spam-quarantine</category><category>tcp-6025</category><category>unauthenticated-rce</category><category>exposure-scanner</category><category>ioc-detection</category><category>backdoor-detection</category><category>python</category></item><item><title>Cisco ASA/FTD WebVPN File-Handler Heap Buffer Overflow Exposure Scanner (CVE-2025-20333)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-20333-cisco-asa-ftd-webvpn-buffer-overflow/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-20333-cisco-asa-ftd-webvpn-buffer-overflow/</guid><description>Critical severity (CVSS 9.9) — network · CVE-2025-20333. Status: PoC. Affects: Cisco Secure ASA and Cisco Secure FTD (WebVPN / AnyConnect file upload handler). Tags: cisco, asa, ftd, webvpn, anyconnect, heap-buffer-overflow, cwe-120, rce-as-root, exposure-scanner, path-traversal, python.</description><category>network</category><category>Critical</category><category>cisco</category><category>asa</category><category>ftd</category><category>webvpn</category><category>anyconnect</category><category>heap-buffer-overflow</category><category>cwe-120</category><category>rce-as-root</category><category>exposure-scanner</category><category>path-traversal</category><category>python</category></item><item><title>ASP.NET Core Kestrel HTTP Request Smuggling (CVE-2025-55315)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-55315-kestrel-http-request-smuggling/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-55315-kestrel-http-request-smuggling/</guid><description>Critical severity (CVSS 9.9) — network · CVE-2025-55315. Status: Weaponized. Affects: ASP.NET Core Kestrel web server (Microsoft.AspNetCore.Server.Kestrel). Tags: aspnet-core, kestrel, http-request-smuggling, chunked-transfer-encoding, dotnet, python, cwe-444, ssrf, cache-poisoning, webshell-upload.</description><category>network</category><category>Critical</category><category>aspnet-core</category><category>kestrel</category><category>http-request-smuggling</category><category>chunked-transfer-encoding</category><category>dotnet</category><category>python</category><category>cwe-444</category><category>ssrf</category><category>cache-poisoning</category><category>webshell-upload</category></item><item><title>Zyxel VMG3625-T50B Authenticated Command Injection to Root SSH Access (CVE-2026-1459)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-1459-zyxel-router-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-1459-zyxel-router-command-injection/</guid><description>High severity — network · CVE-2026-1459. Status: PoC. Affects: Zyxel VMG3625-T50B (and similar) router firmware. Tags: zyxel, router, firmware, command-injection, cgi-bin, ssh, authenticated, iot.</description><category>network</category><category>High</category><category>zyxel</category><category>router</category><category>firmware</category><category>command-injection</category><category>cgi-bin</category><category>ssh</category><category>authenticated</category><category>iot</category></item><item><title>ZTE ZXHN H298A / H108N Router Unauthenticated Credential Disclosure (CVE-2026-34474)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34474-zte-router-sensitive-data-exposure/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34474-zte-router-sensitive-data-exposure/</guid><description>High severity — network · CVE-2026-34474. Status: PoC. Affects: ZTE ZXHN H298A (hardware 1.1) and ZXHN H108N (hardware 2.6) home routers. Tags: information-disclosure, router, firmware, unauthenticated, credential-leak, iot, zte, wifi.</description><category>network</category><category>High</category><category>information-disclosure</category><category>router</category><category>firmware</category><category>unauthenticated</category><category>credential-leak</category><category>iot</category><category>zte</category><category>wifi</category></item><item><title>ZTE ZXHN H188A Unauthenticated Wizard Handler Credential Disclosure / Auth Bypass (CVE-2026-34472)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34472-zte-h188a-auth-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34472-zte-h188a-auth-bypass/</guid><description>Critical severity — network · CVE-2026-34472. Status: PoC. Affects: ZTE ZXHN H188A V6 home router firmware. Tags: router, firmware, unauthenticated, auth-bypass, credential-leak, iot, zte, wifi.</description><category>network</category><category>Critical</category><category>router</category><category>firmware</category><category>unauthenticated</category><category>auth-bypass</category><category>credential-leak</category><category>iot</category><category>zte</category><category>wifi</category></item><item><title>ZTE Router Unauthenticated Oversized-POST Denial of Service (CVE-2026-34473)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34473-zte-router-dos/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-34473-zte-router-dos/</guid><description>High severity — network · CVE-2026-34473. Status: PoC. Affects: ZTE H-series routers (17+ models, reported as affecting 140K+ devices). Tags: router, firmware, unauthenticated, denial-of-service, iot, zte, cgilua, web-interface.</description><category>network</category><category>High</category><category>router</category><category>firmware</category><category>unauthenticated</category><category>denial-of-service</category><category>iot</category><category>zte</category><category>cgilua</category><category>web-interface</category></item><item><title>ZAI-Shell — Unauthenticated Remote Code Execution via P2P Terminal Sharing (CVE-2026-25807)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-25807-zai-shell-p2p-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-25807-zai-shell-p2p-rce/</guid><description>Critical severity — network · CVE-2026-25807. Status: PoC. Affects: ZAI-Shell (P2P terminal-sharing tool). Tags: zai-shell, p2p, rce, unauthenticated, terminal-sharing, socket, no-ai-mode, remote-command-execution.</description><category>network</category><category>Critical</category><category>zai-shell</category><category>p2p</category><category>rce</category><category>unauthenticated</category><category>terminal-sharing</category><category>socket</category><category>no-ai-mode</category><category>remote-command-execution</category></item><item><title>YAMCS LdapAuthModule LDAP Injection Authentication Bypass (CVE-2026-42568)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-42568-yamcs-ldap-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-42568-yamcs-ldap-injection/</guid><description>Medium severity — network · CVE-2026-42568 / GHSA-cqh3-jg8p-336j. Status: PoC. Affects: YAMCS (org.yamcs.security.LdapAuthModule). Tags: ldap-injection, authentication-bypass, yamcs, ldap, python, cwe-90.</description><category>network</category><category>Medium</category><category>ldap-injection</category><category>authentication-bypass</category><category>yamcs</category><category>ldap</category><category>python</category><category>cwe-90</category></item><item><title>Wyze Cam Pan v3 / TUTK SDK — tutk_packet_alloc Heap Overflow (CVE-2026-38698)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38698-wyze-cam-tutk-heap-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38698-wyze-cam-tutk-heap-overflow/</guid><description>Critical severity — network · CVE-2026-38698. Status: PoC. Affects: TUTK SDK (as used in Wyze Cam Pan v3 and other TUTK-based IoT cameras). Tags: tutk-sdk, iot, camera, heap-overflow, av-server, wyze, authenticated, p2p.</description><category>network</category><category>Critical</category><category>tutk-sdk</category><category>iot</category><category>camera</category><category>heap-overflow</category><category>av-server</category><category>wyze</category><category>authenticated</category><category>p2p</category></item><item><title>Windows Server 2025 Local NTLM Reflection LPE via SMB Arbitrary Port + PetitPotam (CVE-2026-24294)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-24294-petitpotam-smb-ntlm-reflection-lpe/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-24294-petitpotam-smb-ntlm-reflection-lpe/</guid><description>Critical severity — network · CVE-2026-24294 (Microsoft Security Response Center). Status: Weaponized. Affects: Windows Server 2025 (SMB client "arbitrary TCP port" feature). Tags: ntlm-relay, smb, petitpotam, windows-server-2025, local-privilege-escalation, lsass, coercion, impacket.</description><category>network</category><category>Critical</category><category>ntlm-relay</category><category>smb</category><category>petitpotam</category><category>windows-server-2025</category><category>local-privilege-escalation</category><category>lsass</category><category>coercion</category><category>impacket</category></item><item><title>Windows Kerberos Reflection via Unicode SPN Normalization Bypass (CVE-2026-26128)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-26128-adcs-kerberos-relay-unicode-spn/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-26128-adcs-kerberos-relay-unicode-spn/</guid><description>Critical severity — network · CVE-2026-26128. Status: Weaponized. Affects: Windows Active Directory (DnsCache SPN resolution / Kerberos authentication). Tags: kerberos-relay, active-directory, adcs, unicode-normalization, spn-spoofing, ntlm-relay, dns-spoofing, privilege-escalation.</description><category>network</category><category>Critical</category><category>kerberos-relay</category><category>active-directory</category><category>adcs</category><category>unicode-normalization</category><category>spn-spoofing</category><category>ntlm-relay</category><category>dns-spoofing</category><category>privilege-escalation</category></item><item><title>Windows ikeext.dll IKEv2 Double-Free Remote Kernel Exploit — CVE-2026-33824</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-33824-ikev2-ikeext-double-free-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-33824-ikev2-ikeext-double-free-rce/</guid><description>Critical severity — network · CVE-2026-33824. Status: Weaponized. Affects: Windows IKEv2 IPsec driver (ikeext.dll). Tags: ikev2, windows-kernel, double-free, ikeext, rop-chain, heap-grooming, reverse-shell, anti-debug, packet-fragmentation.</description><category>network</category><category>Critical</category><category>ikev2</category><category>windows-kernel</category><category>double-free</category><category>ikeext</category><category>rop-chain</category><category>heap-grooming</category><category>reverse-shell</category><category>anti-debug</category><category>packet-fragmentation</category></item><item><title>Unauthenticated NaN Injection via MAVLink PARAM_SET in ArduPilot ArduPlane (CVE-2026-36522)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-36522-ardupilot-mavlink-nan-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-36522-ardupilot-mavlink-nan-injection/</guid><description>Critical severity (CVSS 9.1) — network · CVE-2026-36522. Status: Weaponized. Affects: ArduPilot ArduPlane. Tags: ardupilot, mavlink, drone, nan-injection, unauthenticated, cwe-1287.</description><category>network</category><category>Critical</category><category>ardupilot</category><category>mavlink</category><category>drone</category><category>nan-injection</category><category>unauthenticated</category><category>cwe-1287</category></item><item><title>TP-Link Tapo C260 Unauthenticated-to-Root RCE Chain — CVE-2026-0651</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-0651-tapo-c260-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-0651-tapo-c260-rce/</guid><description>Critical severity — network · CVE-2026-0651 (chained with CVE-2026-0652, CVE-2026-0653). Status: Weaponized. Affects: TP-Link Tapo C260 IP camera (pre-patch firmware, shared /bin/main omnibus binary across models). Tags: iot, ip-camera, tp-link, tapo, path-traversal, command-injection, privilege-escalation, exploit-chain.</description><category>network</category><category>Critical</category><category>iot</category><category>ip-camera</category><category>tp-link</category><category>tapo</category><category>path-traversal</category><category>command-injection</category><category>privilege-escalation</category><category>exploit-chain</category></item><item><title>TP-Link DHCP Option 66 Unauthenticated RCE — CVE-2026-11834</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-11834-tplink-dhcp-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-11834-tplink-dhcp-rce/</guid><description>Critical severity — network · CVE-2026-11834. Status: Weaponized. Affects: TP-Link router firmware (libcmm.so DHCP client), tested on Archer C20 V6. Tags: tp-link, router, dhcp, command-injection, cwe-78, race-condition, rce, iot.</description><category>network</category><category>Critical</category><category>tp-link</category><category>router</category><category>dhcp</category><category>command-injection</category><category>cwe-78</category><category>race-condition</category><category>rce</category><category>iot</category></item><item><title>TP-Link Archer C64 Web UI Rate-Limit Bypass via Residual Debug SSH Service (CVE-2026-8697)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-8697-tplink-archer-c64-ssh-ratelimit-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-8697-tplink-archer-c64-ssh-ratelimit-bypass/</guid><description>Critical severity (CVSS 9.3) — network · CVE-2026-8697. Status: PoC. Affects: TP-Link Archer C64 router firmware ("TPOS"). Tags: tplink, archer-c64, router, ssh, rate-limit-bypass, authentication-oracle, brute-force, iot.</description><category>network</category><category>Critical</category><category>tplink</category><category>archer-c64</category><category>router</category><category>ssh</category><category>rate-limit-bypass</category><category>authentication-oracle</category><category>brute-force</category><category>iot</category></item><item><title>Tenda HG7/HG9/HG10 Router Stack-Based Buffer Overflow — CVE-2026-11499</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-11499-tenda-router-bof/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-11499-tenda-router-bof/</guid><description>High severity — network · CVE-2026-11499. Status: PoC. Affects: Tenda HG7 / HG9 / HG10 routers (firmware family HG7_HG9_HG10re_300001138_en_xpon and similar). Tags: tenda, router, buffer-overflow, cwe-121, dos, embedded, iot, rce.</description><category>network</category><category>High</category><category>tenda</category><category>router</category><category>buffer-overflow</category><category>cwe-121</category><category>dos</category><category>embedded</category><category>iot</category><category>rce</category></item><item><title>Tasmota fetch_jpg() strcpy() Buffer Overflow in boundary[40] (CVE-2026-38426)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38426-tasmota-fetchjpg-strcpy-overflow/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-38426-tasmota-fetchjpg-strcpy-overflow/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-38426. Status: PoC. Affects: Arendst Tasmota (ESP32 firmware). Tags: tasmota, esp32, iot, buffer-overflow, strcpy, rce, mjpeg, scripter.</description><category>network</category><category>Critical</category><category>tasmota</category><category>esp32</category><category>iot</category><category>buffer-overflow</category><category>strcpy</category><category>rce</category><category>mjpeg</category><category>scripter</category></item></channel></rss>