Warning: Undefined array key 0 in /var/www/tgoop/function.php on line 65

Warning: Trying to access array offset on value of type null in /var/www/tgoop/function.php on line 65
12554 - Telegram Web
Telegram Web
Forwarded from /g/‘s Tech Memes
Micromanagement hell
There's a critical vulnerability in D-Link NAS devices (CVE-2024-10914: NVD Details) that allows anyone to execute arbitrary commands via an HTTP request.
D-Link won’t fix it, claiming the affected devices are too old—even though some are under 10 years old.

In a technical write-up that provides exploit details, security researcher Netsecfish says that leveraging the vulnerability requires sending "a crafted HTTP GET request to the NAS device with malicious input in the name parameter.”

curl "http://[Target-IP]/cgi-bin/account_mgr.cgi cmd=cgi_user_add&name=%27;<INJECTED_SHELL_COMMAND>;%27" 


Bleeping Computer Article

YouTube Technical Breakdown by Low Level
Forwarded from bread's memehole (bread (very fragile))
HEY BITCHES THEY JUST DISCLOSED AN RCE IN 7-ZIP GO MAKE SURE YOU HAVE THE LATEST VERSION INSTALLED RIGHT NOW!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! :)

https://www.cve.org/CVERecord?id=CVE-2024-11477
This media is not supported in your browser
VIEW IN TELEGRAM
Using a laser to remove church bench varnish makes it a pew pew pew
2025/07/14 06:33:37
Back to Top
HTML Embed Code: