CVE HUB ๐Ÿ‘พ
788 subscribers
19.3K links
Github Red team resource push
Github ็บข้˜Ÿ่ต„ๆบๆŽจ้€
Cve/Rce/Exploit/Redteam/ๆผๆดžๅˆฉ็”จ/็บข้˜Ÿ

Channel push 24/7 (real time)
้ข‘้“ๅ…จๅคฉๅ€™ๆŽจ้€(ๅฎžๆ—ถ)
Download Telegram
๐Ÿ‘พCVE SERVICE ๐Ÿท#CVE
Mumber: CVE-2022-31479
Github: https://github.com/realyme/CVE-2022-31479-test
Describe:
An unauthenticated attacker can update the hostname with a specially crafted name that will allow for shell commands to be executed during the core collection process. This vulnerability impacts products based on HID Mercury Intelligent Controllers LP1501, LP1502, LP2500, LP4502, and EP4502 which contain firmware versions prior to 1.302 for the LP series and 1.296 for the EP series. An attacker with this level of access on the device can monitor all communications sent to and from this device, modify onboard relays, change configuration files, or cause the device to become unstable. The injected commands only get executed during start up or when unsafe calls regarding the hostname are used. This allows the attacker to gain remote access to the device and can make their persistence permanent by modifying the filesystem.
๐Ÿ‘พCVE SERVICE ๐Ÿท#CVE
Mumber: CVE-2022-1976
Github: https://github.com/h4ckdepy/CVE-2022-1976
Describe:
A flaw was found in the Linux kernel’s implementation of IO-URING. This flaw allows an attacker with local executable permission to create a string of requests that can cause a use-after-free flaw within the kernel. This issue leads to memory corruption and possible privilege escalation.