<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Root — PoC Archive</title><link>https://poc.intelseclab.com/tags/root/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 05 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/root/index.xml" rel="self" type="application/rss+xml"/><item><title>Realtek rtl819x Jungle SDK Unauthenticated Kernel Memory R/W via Debug IOCTLs (CVE-2026-36355)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-36355-realtek-rtl819x-kernel-memory-rw/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-36355-realtek-rtl819x-kernel-memory-rw/</guid><description>Critical severity — network · CVE-2026-36355. Status: Weaponized. Affects: Realtek rtl819x "Jungle SDK" out-of-tree Wi-Fi driver (rtl8192cd). Tags: realtek, rtl819x, router-firmware, kernel-memory, ioctl, wifi-driver, root, cwe-782, cwe-787, cwe-200.</description><category>network</category><category>Critical</category><category>realtek</category><category>rtl819x</category><category>router-firmware</category><category>kernel-memory</category><category>ioctl</category><category>wifi-driver</category><category>root</category><category>cwe-782</category><category>cwe-787</category><category>cwe-200</category></item><item><title>OpenRemote — Expression Injection RCE in Rules Engine (CVE-2026-39842)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39842-openremote-expression-injection-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-39842-openremote-expression-injection-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-39842 / GHSA-7mqr-33rv-p3mp. Status: Weaponized. Affects: OpenRemote (IoT device/rules management platform). Tags: openremote, iot, nashorn, javascript-injection, rules-engine, rce, authenticated, root.</description><category>web</category><category>Critical</category><category>openremote</category><category>iot</category><category>nashorn</category><category>javascript-injection</category><category>rules-engine</category><category>rce</category><category>authenticated</category><category>root</category></item><item><title>OpenLearnX Unauthenticated RCE via Container Volume Mount (CVE-2026-41900)</title><link>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-41900-openlearnx-container-volume-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/cloud/2026-07-05_cve-2026-41900-openlearnx-container-volume-rce/</guid><description>High severity (CVSS 8.6) — cloud · CVE-2026-41900 (GHSA-8h25-q488-4hxw). Status: PoC. Affects: OpenLearnX code-execution/compiler service (Flask backend). Tags: docker, container-escape, rce, unauthenticated, code-execution-sandbox, info-disclosure, volume-mount, root.</description><category>cloud</category><category>High</category><category>docker</category><category>container-escape</category><category>rce</category><category>unauthenticated</category><category>code-execution-sandbox</category><category>info-disclosure</category><category>volume-mount</category><category>root</category></item><item><title>MeiG Smart FORGE_SLT711 GoAhead Unauthenticated OS Command Injection (CVE-2026-36356)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-36356-meig-smart-router-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-36356-meig-smart-router-command-injection/</guid><description>Critical severity — network · CVE-2026-36356. Status: Weaponized. Affects: MeiG Smart FORGE_SLT711 4G LTE CPE (GoAhead web server). Tags: meig-smart, 4g-lte-cpe, router, command-injection, goahead, unauthenticated, root, cwe-78, cwe-306.</description><category>network</category><category>Critical</category><category>meig-smart</category><category>4g-lte-cpe</category><category>router</category><category>command-injection</category><category>goahead</category><category>unauthenticated</category><category>root</category><category>cwe-78</category><category>cwe-306</category></item><item><title>Cisco Catalyst SD-WAN Manager Privilege Escalation (CVE-2026-20245)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-20245-cisco-sdwan-priv-esc/</link><pubDate>Sun, 28 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-28_cve-2026-20245-cisco-sdwan-priv-esc/</guid><description>High severity (CVSS 7.8) — network · CVE-2026-20245. Status: PoC. Affects: Cisco Catalyst SD-WAN Manager (vManage), SD-WAN Controller (vSmart), SD-WAN Validator (vBond). Tags: privilege-escalation, Cisco, SD-WAN, vManage, file-upload, command-injection, root, CISA-KEV, no-patch, Mandiant, nation-state.</description><category>network</category><category>High</category><category>privilege-escalation</category><category>Cisco</category><category>SD-WAN</category><category>vManage</category><category>file-upload</category><category>command-injection</category><category>root</category><category>CISA-KEV</category><category>no-patch</category><category>Mandiant</category><category>nation-state</category></item><item><title>TossUp — TerraMaster TOS Unauthenticated Redis Root RCE + NFS LPE</title><link>https://poc.intelseclab.com/pocs/network/2026-05-18_tossup-terramaster-redis-rce/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-18_tossup-terramaster-redis-rce/</guid><description>Critical severity — network · N/A (vendor confirmed TOS4 is EOL; no fix planned). Status: Weaponized. Affects: TerraMaster TOS3_A1.0 4.2.41, Redis 4.0.10. Tags: RCE, unauthenticated, Redis, TerraMaster, NAS, AArch64, root, module-loading, replication-abuse, NFS, no_root_squash, LPE, network.</description><category>network</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>Redis</category><category>TerraMaster</category><category>NAS</category><category>AArch64</category><category>root</category><category>module-loading</category><category>replication-abuse</category><category>NFS</category><category>no_root_squash</category><category>LPE</category><category>network</category></item></channel></rss>