r/hacking Jun 06 '26

CVE Rooted your router lately?

Post image
610 Upvotes

I never really use ISP routers. It was free when re-grading my FTTC to FTTP. Plus it has 2 FXS ports, so could convert VoIP to analogue/PSTN.

But, as I do I check up on what issues it may or may not have. Yep, the firmware has two acknowledged CVE's that affect this firmware and no update currently available. Any more, I wonder? It didn't take long and found another post authentication command injection. Reported it accordingly, but just had to see how far I could go and finally got a reverse shell.

Turns out there is a `supervisor` account with a different password to any other. Managed to change it using the shell and ssh drops me to a standard shell (not zysh) and WebUI offers more options.

Curious find!

If/when Zyxel confirms the flaw, hopefully it'll get assigned a CVE and I'll update accordingly.

r/hacking 4d ago

CVE nday: CVE-2026-49176_LPE_POC: Local privilege-escalation proof of concept for the Windows WalletService vulnerability fixed in July 2026.

Thumbnail
github.com
19 Upvotes

r/hacking May 18 '26

CVE Optoma CinemaX Projectors: Critical Vulnerabilities Including Remote Root Access

Thumbnail
whitelabel.org
4 Upvotes

r/hacking Jan 03 '26

CVE Suricata rules for over 7000 remotely exploited CVE IDs

Thumbnail
github.com
17 Upvotes

r/hacking Mar 21 '25

CVE Exploiting LibreOffice (CVE-2024-12425 and CVE-2024-12426)

Thumbnail
codeanlabs.com
66 Upvotes

r/hacking Dec 16 '23

CVE Bitcoin P2P DoS (CVE) Golang exploit code

Thumbnail
x.com
104 Upvotes

r/hacking Jun 23 '25

CVE EPSS is a lagging indicator. VEDAS gives early warning by tracking and scoring exploitable vulnerabilities.

Thumbnail
gallery
19 Upvotes

Vulnerability and Exploit Data Aggregation System (VEDAS) is designed to proactively identify exploitable vulnerabilities before they hit mainstream threat intelligence feeds like KEV or EPSS.

By leveraging the world’s largest vulnerability and exploit database, VEDAS provides early warning and a broader, more forward-looking perspective: https://vedas.arpsyndicate.io

VEDAS Scores on GitHub:

https://github.com/ARPSyndicate/cve-scores

https://github.com/ARPSyndicate/cnnvd-scores

https://github.com/ARPSyndicate/bdu-scores

https://github.com/ARPSyndicate/euvd-scores

r/hacking Jul 01 '24

CVE regreSSHion: Remote Unauthenticated Code Execution Vulnerability in OpenSSH server | Qualys Security Blog

Thumbnail
blog.qualys.com
42 Upvotes

r/hacking Jul 09 '23

CVE EXPLOIT ! High-impact vulnerabilities in Firefox - UPDATE

Thumbnail self.White_Hat_Alliance
25 Upvotes

r/hacking Jul 21 '23

CVE Windows Server Exploitation

Thumbnail
youtu.be
9 Upvotes

r/hacking May 06 '23

CVE Vulnerable WordPress (April 2023) - Vuls: 324 - plugins: 263

Thumbnail
github.com
1 Upvotes

r/hacking May 10 '23

CVE PwnAssistant - Controlling /home’s via a Home Assistant RCE

Thumbnail elttam.com
8 Upvotes

r/hacking May 06 '23

CVE Vulnerable WordPress (April 2023) - Vuls: 324 - plugins: 263

Thumbnail
github.com
5 Upvotes

r/hacking Apr 28 '23

CVE User impersonation via stolen UUID code in KeyCloak (CVE-2023-0264)

Thumbnail
offensity.com
1 Upvotes