<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ssh — PoC Archive</title><link>https://poc.intelseclab.com/tags/ssh/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 06 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/ssh/index.xml" rel="self" type="application/rss+xml"/><item><title>FortiOS/FortiProxy/FortiSwitchManager/FortiWeb FortiCloud SSO Authentication Bypass Detection Tool (CVE-2025-59718)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-59718-fortios-version-detection-scanner/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-06_cve-2025-59718-fortios-version-detection-scanner/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2025-59718 (Fortinet advisory FG-IR-25-647; related: CVE-2025-59719). Status: PoC. Affects: Fortinet FortiOS, FortiProxy, FortiSwitchManager, FortiWeb. Tags: fortinet, fortios, fortiproxy, fortiswitchmanager, fortiweb, forticloud-sso, authentication-bypass, version-detection, ssh, scanner, cwe-347.</description><category>network</category><category>Critical</category><category>fortinet</category><category>fortios</category><category>fortiproxy</category><category>fortiswitchmanager</category><category>fortiweb</category><category>forticloud-sso</category><category>authentication-bypass</category><category>version-detection</category><category>ssh</category><category>scanner</category><category>cwe-347</category></item><item><title>Zyxel VMG3625-T50B Authenticated Command Injection to Root SSH Access (CVE-2026-1459)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-1459-zyxel-router-command-injection/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-1459-zyxel-router-command-injection/</guid><description>High severity — network · CVE-2026-1459. Status: PoC. Affects: Zyxel VMG3625-T50B (and similar) router firmware. Tags: zyxel, router, firmware, command-injection, cgi-bin, ssh, authenticated, iot.</description><category>network</category><category>High</category><category>zyxel</category><category>router</category><category>firmware</category><category>command-injection</category><category>cgi-bin</category><category>ssh</category><category>authenticated</category><category>iot</category></item><item><title>TP-Link Archer C64 Web UI Rate-Limit Bypass via Residual Debug SSH Service (CVE-2026-8697)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-8697-tplink-archer-c64-ssh-ratelimit-bypass/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-05_cve-2026-8697-tplink-archer-c64-ssh-ratelimit-bypass/</guid><description>Critical severity (CVSS 9.3) — network · CVE-2026-8697. Status: PoC. Affects: TP-Link Archer C64 router firmware ("TPOS"). Tags: tplink, archer-c64, router, ssh, rate-limit-bypass, authentication-oracle, brute-force, iot.</description><category>network</category><category>Critical</category><category>tplink</category><category>archer-c64</category><category>router</category><category>ssh</category><category>rate-limit-bypass</category><category>authentication-oracle</category><category>brute-force</category><category>iot</category></item><item><title>Termix Stored XSS via Malicious SVG Upload -> LFI / Session Hijack (CVE-2026-22804 / GHSA-m3cv-5hgp-hv35)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-22804-termix-stored-xss/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-22804-termix-stored-xss/</guid><description>High severity — web · CVE-2026-22804 (GHSA-m3cv-5hgp-hv35). Status: Weaponized. Affects: Termix (Electron-based SSH/terminal manager), File Manager component (FileViewer.tsx). Tags: termix, electron, stored-xss, svg-injection, session-hijacking, lfi, file-manager, ssh.</description><category>web</category><category>High</category><category>termix</category><category>electron</category><category>stored-xss</category><category>svg-injection</category><category>session-hijacking</category><category>lfi</category><category>file-manager</category><category>ssh</category></item><item><title>Cockpit Unauthenticated Remote Code Execution via SSH Argument Injection (CVE-2026-4631)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4631-cockpit-ssh-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-4631-cockpit-ssh-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-4631 (GHSA-m4gv-x78h-3427). Status: PoC. Affects: Cockpit (Linux web-based server admin console). Tags: cockpit, ssh, command-injection, argument-injection, cwe-78, unauthenticated-rce, proxycommand.</description><category>web</category><category>Critical</category><category>cockpit</category><category>ssh</category><category>command-injection</category><category>argument-injection</category><category>cwe-78</category><category>unauthenticated-rce</category><category>proxycommand</category></item><item><title>libssh2 Unchecked SSH packet_length Integer Wrap to RCE (CVE-2026-55200)</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_cve-2026-55200-libssh2-packet-length-rce/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_cve-2026-55200-libssh2-packet-length-rce/</guid><description>Critical severity — network · CVE-2026-55200. Status: Weaponized. Affects: libssh2, ssh2_transport_read() in src/transport.c. Tags: libssh2, ssh, integer-overflow, heap-overflow, packet-length, transport, rce, memory-corruption, cve-2026-55200.</description><category>network</category><category>Critical</category><category>libssh2</category><category>ssh</category><category>integer-overflow</category><category>heap-overflow</category><category>packet-length</category><category>transport</category><category>rce</category><category>memory-corruption</category><category>cve-2026-55200</category></item><item><title>libssh2 Publickey Subsystem List Parser Heap Corruption to Code Execution</title><link>https://poc.intelseclab.com/pocs/network/2026-07-03_libssh2-publickey-list-parser-oob/</link><pubDate>Fri, 03 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-07-03_libssh2-publickey-list-parser-oob/</guid><description>Critical severity — network · None assigned as of 2026-07-03. Status: Weaponized. Affects: libssh2, publickey subsystem list parser (src/publickey.c). Tags: libssh2, ssh, publickey-subsystem, heap-overflow, use-after-free, integer-overflow, windows, rce, memory-corruption.</description><category>network</category><category>Critical</category><category>libssh2</category><category>ssh</category><category>publickey-subsystem</category><category>heap-overflow</category><category>use-after-free</category><category>integer-overflow</category><category>windows</category><category>rce</category><category>memory-corruption</category></item><item><title>libssh2 SSH Packet Length OOB Heap Write / Unauthenticated RCE (CVE-2026-55200)</title><link>https://poc.intelseclab.com/pocs/network/2026-06-30_cve-2026-55200-libssh2-oob-rce/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-06-30_cve-2026-55200-libssh2-oob-rce/</guid><description>Critical severity (CVSS 9.8) — network · CVE-2026-55200. Status: PoC. Affects: libssh2 (SSH client library). Tags: RCE, OOB-write, heap-corruption, libssh2, SSH, integer-overflow, unauthenticated, C, network.</description><category>network</category><category>Critical</category><category>RCE</category><category>OOB-write</category><category>heap-corruption</category><category>libssh2</category><category>SSH</category><category>integer-overflow</category><category>unauthenticated</category><category>C</category><category>network</category></item><item><title>Erlang/OTP SSH Pre-Auth RCE - CVE-2025-32433</title><link>https://poc.intelseclab.com/pocs/network/2026-05-17_erlang-otp-ssh-preauth-rce/</link><pubDate>Sun, 17 May 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/network/2026-05-17_erlang-otp-ssh-preauth-rce/</guid><description>Critical severity (CVSS 10) — network · CVE-2025-32433. Status: Patched. Affects: Erlang/OTP SSH server daemon. Tags: RCE, pre-auth, unauthenticated, SSH, Erlang, OTP, RabbitMQ, CouchDB, ICS, OT, reverse-shell, in-the-wild.</description><category>network</category><category>Critical</category><category>RCE</category><category>pre-auth</category><category>unauthenticated</category><category>SSH</category><category>Erlang</category><category>OTP</category><category>RabbitMQ</category><category>CouchDB</category><category>ICS</category><category>OT</category><category>reverse-shell</category><category>in-the-wild</category></item></channel></rss>