PoC Archive PoC Archive

tag

Udp

  • CVE-2026-33453 web CRITICAL 9.8

    camel-coap Header Injection → RCE Self-Contained Reproducer (CVE-2026-33453)

    Apache Camel's camel-coap component copies CoAP request URI query parameters directly into Camel Exchange headers inside CamelCoapResource.handleRequest(), without applying any HeaderFilterStrategy. Because CoAPEndpoint extends DefaultEndpoint (not…

    Unverified 2026-07-06
  • CVE-2026-4893 network MEDIUM

    dnsmasq EDNS Client Subnet (ECS) Response Validation Bypass (CVE-2026-4893)

    This PoC demonstrates that dnsmasq, when configured with EDNS Client Subnet (ECS, RFC 7871) via add-subnet, will accept an upstream DNS response carrying an ECS option whose subnet does not match the subnet dnsmasq originally sent in the query. The included…

    Patched 2026-07-05
  • CVE-2026-33453 web CRITICAL 10

    Apache Camel camel-coap Header Injection to Remote Code Execution (CVE-2026-33453)

    Apache Camel's camel-coap component maps CoAP URI query parameters directly into Camel Exchange headers via setHeader() inside CamelCoapResource.handleRequest(), without applying any HeaderFilterStrategy. Because CoAPEndpoint extends DefaultEndpoint rather…

    Patched 2026-07-05
  • CVE-2026-12485 network CRITICAL 10

    GeoVision GV-I/O Box 4E DVRSearch Unauthenticated Stack Buffer Overflow RCE (CVE-2026-12485)

    CVE-2026-12485 is a CVSS 10.0 unauthenticated stack-based buffer overflow in the GeoVision GV-I/O Box 4E, a Linux-based smart I/O device used in physical security and building automation. The DVRSearch service listens on UDP port 10001 and handles CMDIPSET…

    Patched 2026-06-30