CWE-506
Allowed-with-ReviewEmbedded Malicious Code
Abstraction: Class · Status: Incomplete
The product contains code that appears to be malicious in nature.
553 vulnerabilities reference this CWE, most recent first.
CVE-2026-97230 (GCVE-0-2026-97230)
Vulnerability from cvelistv5 – Published: 2026-09-24 22:36 – Updated: 2026-09-25 16:11- CWE-506 - Embedded Malicious Code
| URL | Tags |
|---|---|
| https://www.nntp.perl.org/group/perl.cpan.testers… | vendor-advisory |
| https://www.cve.org/CVERecord?id=CVE-2026-95831 | related |
{
"containers": {
"adp": [
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2026-97230",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-25T16:11:04.730543Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T16:11:11.028Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://cpan.org/modules",
"defaultStatus": "unaffected",
"modules": [
"IO::Socket::SSL::SelfCertificate"
],
"packageName": "IO-Socket-SSL-SelfCertificate",
"packageURL": "pkg:cpan/IO-Socket-SSL-SelfCertificate",
"programFiles": [
"lib/IO/Socket/SSL/SelfCertificate.pm",
"lib/IO/Socket/SSL/SelfCertificate/sample/cert.pem"
],
"versions": [
{
"status": "affected",
"version": "1.00",
"versionType": "custom"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL.\n\nThe generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly.\n\nThe impact is that arbitrary code can be invoked as the user, without a dropped script being saved on the affected host.\n\nThe releases have no test scripts nor build hooks. The intention may have been to trigger the payload after installation.\n\nThe dropper script is in lib/Crypt/SelfCertificate/sample/cert.pem.\n\nThis is similar to CVE-2026-95831 for the module Crypt::SelfCertificate.\n\nThe SHA-256 digests of the files are\n\n ba24ee8ec3b7f47f65bed62e16fb413ace50653cf44bd8ea90914390922831e0 IO-Socket-SSL-SelfCertificate-1.00.tar.gz\n 821d38830e5eb8607738421c25ac25f59fff02a6ab67daa32fbd020429454dac IO-Socket-SSL-SelfCertificate-1.00/lib/IO/Socket/SSL/SelfCertificate/sample/cert.pem\n\n d483cb7b23b7271cb11cf242bff4a2e1c02df0b9525eb0429abeea8961c399d5 IO-Socket-SSL-SelfCertificate-1.00-upload.tar.gz"
}
],
"impacts": [
{
"capecId": "CAPEC-253",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-253 Remote Code Inclusion"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-506",
"description": "CWE-506 Embedded Malicious Code",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T22:36:50.882Z",
"orgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"shortName": "CPANSec"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://www.nntp.perl.org/group/perl.cpan.testers.discuss/2026/09/msg4756.html"
},
{
"tags": [
"related"
],
"url": "https://www.cve.org/CVERecord?id=CVE-2026-95831"
}
],
"solutions": [
{
"lang": "en",
"value": "Systems on which the affected package was installed should be considered potentially compromised and investigated accordingly."
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL",
"x_generator": {
"engine": "cpansec-cna-tool 0.1"
}
}
},
"cveMetadata": {
"assignerOrgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"assignerShortName": "CPANSec",
"cveId": "CVE-2026-97230",
"datePublished": "2026-09-24T22:36:50.882Z",
"dateReserved": "2026-09-24T10:09:37.672Z",
"dateUpdated": "2026-09-25T16:11:11.028Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-95831 (GCVE-0-2026-95831)
Vulnerability from cvelistv5 – Published: 2026-09-22 18:21 – Updated: 2026-09-23 16:09- CWE-506 - Embedded Malicious Code
{
"containers": {
"adp": [
{
"providerMetadata": {
"dateUpdated": "2026-09-23T16:09:02.987Z",
"orgId": "af854a3a-2127-422b-91ae-364da2661108",
"shortName": "CVE"
},
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2026/09/22/21"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/09/23/2"
},
{
"url": "http://www.openwall.com/lists/oss-security/2026/09/23/3"
}
],
"title": "CVE Program Container"
},
{
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "LOCAL",
"availabilityImpact": "HIGH",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "REQUIRED",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"version": "3.1"
}
},
{
"other": {
"content": {
"id": "CVE-2026-95831",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T20:13:35.298576Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T20:13:37.851Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://cpan.org/modules",
"defaultStatus": "unaffected",
"modules": [
"Crypt::SelfCertificate"
],
"packageName": "Crypt-SelfCertificate",
"packageURL": "pkg:cpan/Crypt-SelfCertificate",
"programFiles": [
"lib/Crypt/SelfCertificate.pm",
"lib/Crypt/SelfCertificate/sample/validate.p12",
"lib/Crypt/SelfCertificate/sample/cert7.pem"
],
"versions": [
{
"lessThanOrEqual": "1.05",
"status": "affected",
"version": "1.01",
"versionType": "custom"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL.\n\nThe generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly.\n\nThe impact is that arbitrary code can be invoked as the user, without a dropped script being saved on the affected host.\n\nThe releases have no test scripts nor build hooks. The intention may have been to trigger the payload after installation.\n\nFor version 1.01, the dropper script is in lib/Crypt/SelfCertificate/sample/validate.p12.\n\nFor version 1.05, the dropper script is in lib/Crypt/SelfCertificate/sample/cert7.pem.\n\nThe SHA-256 digests of the files are\n\n fbff21f45ff748365062a5e36fb2d72558cad82a507a6f357f320b4fcdf07760 Crypt-SelfCertificate-1.01.tar.gz\n 27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/validate.p12\n\n 9fdfa7d69b034b77d4510cda567e8da1e486ca81c7daaadc5732a45c41d71991 Crypt-SelfCertificate-1.05.tar.gz\n 27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/cert7.pem"
}
],
"impacts": [
{
"capecId": "CAPEC-253",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-253 Remote Code Inclusion"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-506",
"description": "CWE-506 Embedded Malicious Code",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T18:21:23.728Z",
"orgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"shortName": "CPANSec"
},
"references": [
{
"tags": [
"vendor-advisory"
],
"url": "https://www.nntp.perl.org/group/perl.cpan.testers.discuss/2026/09/msg4754.html"
}
],
"solutions": [
{
"lang": "en",
"value": "Systems on which the affected package was installed should be considered potentially compromised and investigated accordingly."
}
],
"source": {
"discovery": "UNKNOWN"
},
"timeline": [
{
"lang": "en",
"time": "2026-09-15T00:00:00.000Z",
"value": "Crypt::SelfCertificate version 1.00 uploaded to CPAN"
},
{
"lang": "en",
"time": "2026-09-17T00:00:00.000Z",
"value": "Crypt::SelfCertificate version 1.01 uploaded to CPAN"
},
{
"lang": "en",
"time": "2026-09-22T00:00:00.000Z",
"value": "Crypt::SelfCertificate version 1.05 uploaded to CPAN"
},
{
"lang": "en",
"time": "2026-09-22T00:00:00.000Z",
"value": "Malware identified by CPANSec scanning"
}
],
"title": "Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL",
"x_generator": {
"engine": "cpansec-cna-tool 0.1"
}
}
},
"cveMetadata": {
"assignerOrgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
"assignerShortName": "CPANSec",
"cveId": "CVE-2026-95831",
"datePublished": "2026-09-22T18:21:23.728Z",
"dateReserved": "2026-09-22T16:29:23.694Z",
"dateUpdated": "2026-09-23T16:09:02.987Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-77651 (GCVE-0-2026-77651)
Vulnerability from cvelistv5 – Published: 2026-08-21 00:41 – Updated: 2026-08-21 13:17- CWE-506 - Embedded Malicious Code
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-77651",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-21T13:17:41.622051Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T13:17:52.920Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "arrayref",
"vendor": "droundy",
"versions": [
{
"status": "affected",
"version": "0.3.10",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-506",
"description": "CWE-506 Embedded Malicious Code",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T00:41:36.099Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref"
},
{
"url": "https://github.com/rustsec/advisory-db/issues/3161"
},
{
"url": "https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack"
},
{
"url": "https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/"
},
{
"url": "https://rustsec.org/advisories/RUSTSEC-2026-0260.html"
}
],
"x_generator": {
"engine": "CVE-Request-form 0.0.1"
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2026-77651",
"datePublished": "2026-08-21T00:41:36.099Z",
"dateReserved": "2026-08-21T00:41:35.750Z",
"dateUpdated": "2026-08-21T13:17:52.920Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-77650 (GCVE-0-2026-77650)
Vulnerability from cvelistv5 – Published: 2026-08-21 00:40 – Updated: 2026-08-21 13:20- CWE-506 - Embedded Malicious Code
| Vendor | Product | Version | |
|---|---|---|---|
| droundy | append-only-vec |
Affected:
0.1.9
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-77650",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-21T13:18:56.634996Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T13:20:06.921Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "append-only-vec",
"vendor": "droundy",
"versions": [
{
"status": "affected",
"version": "0.1.9",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-506",
"description": "CWE-506 Embedded Malicious Code",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T00:40:26.467Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref"
},
{
"url": "https://github.com/rustsec/advisory-db/issues/3161"
},
{
"url": "https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack"
},
{
"url": "https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/"
},
{
"url": "https://rustsec.org/advisories/RUSTSEC-2026-0262.html"
}
],
"x_generator": {
"engine": "CVE-Request-form 0.0.1"
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2026-77650",
"datePublished": "2026-08-21T00:40:26.467Z",
"dateReserved": "2026-08-21T00:40:26.113Z",
"dateUpdated": "2026-08-21T13:20:06.921Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-77649 (GCVE-0-2026-77649)
Vulnerability from cvelistv5 – Published: 2026-08-21 00:39 – Updated: 2026-08-21 13:25- CWE-506 - Embedded Malicious Code
| Vendor | Product | Version | |
|---|---|---|---|
| droundy | internment |
Affected:
0.8.7
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-77649",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-21T13:25:28.760292Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T13:25:41.885Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unaffected",
"product": "internment",
"vendor": "droundy",
"versions": [
{
"status": "affected",
"version": "0.8.7",
"versionType": "semver"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution."
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-506",
"description": "CWE-506 Embedded Malicious Code",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-21T00:39:02.071Z",
"orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"shortName": "mitre"
},
"references": [
{
"url": "https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref"
},
{
"url": "https://github.com/rustsec/advisory-db/issues/3161"
},
{
"url": "https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack"
},
{
"url": "https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/"
},
{
"url": "https://rustsec.org/advisories/RUSTSEC-2026-0266.html"
}
],
"x_generator": {
"engine": "CVE-Request-form 0.0.1"
}
}
},
"cveMetadata": {
"assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
"assignerShortName": "mitre",
"cveId": "CVE-2026-77649",
"datePublished": "2026-08-21T00:39:02.071Z",
"dateReserved": "2026-08-21T00:39:01.558Z",
"dateUpdated": "2026-08-21T13:25:41.885Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-74232 (GCVE-0-2026-74232)
Vulnerability from cvelistv5 – Published: 2026-08-27 10:39 – Updated: 2026-08-27 14:49| URL | Tags |
|---|---|
| http://vulncheck.com/blog/zbt-darklantern-speakingstone | technical-descriptionexploit |
| https://www.vulncheck.com/advisories/zbtlink-mqwr… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Zbtlink | L3_V2_8 |
Affected:
3.0.0.4.528
(custom)
|
|
| Zbtlink | WE826-T2 |
Affected:
19.1101
(custom)
|
|
| Zbtlink | ZBT-7628 |
Affected:
1.0.0.2.007
(custom)
|
|
| Zbtlink | ZBT-ZBT7621 |
Affected:
1.0.0.3.001
(custom)
|
|
| MoreQuick | MQAC-7620 |
Affected:
1.0.0.2.000
(custom)
|
|
| MoreQuick | MQAC-7620A |
Affected:
1.0.0.2.000
(custom)
|
|
| MoreQuick | MQAP-7620 |
Affected:
1.0.0.2.000
(custom)
|
|
| MoreQuick | MQAP-7620A |
Affected:
1.0.0.2.000
(custom)
|
|
| MoreQuick | MQAP-7628 |
Affected:
1.0.0.2.000
(custom)
|
|
| Unknown | AP522 |
Affected:
1.0.0.2.014
(custom)
|
|
| Unknown | AP7628 |
Affected:
3.0.0.4.380
(custom)
|
|
| Unknown | APG721B |
Affected:
19.0809
(custom)
|
|
| Unknown | HC5661A |
Affected:
3.0.0.4.380
(custom)
|
|
| Unknown | HK300 |
Affected:
1.0.0.2.032
(custom)
|
|
| Unknown | MAP-N10 |
Affected:
1.0.0.2.044
(custom)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-74232",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-27T14:48:59.362199Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T14:49:10.575Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "unknown",
"product": "L3_V2_8",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "3.0.0.4.528",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "WE826-T2",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "19.1101",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "ZBT-7628",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "1.0.0.2.007",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "ZBT-ZBT7621",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "1.0.0.3.001",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "MQAC-7620",
"vendor": "MoreQuick",
"versions": [
{
"status": "affected",
"version": "1.0.0.2.000",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "MQAC-7620A",
"vendor": "MoreQuick",
"versions": [
{
"status": "affected",
"version": "1.0.0.2.000",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "MQAP-7620",
"vendor": "MoreQuick",
"versions": [
{
"status": "affected",
"version": "1.0.0.2.000",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "MQAP-7620A",
"vendor": "MoreQuick",
"versions": [
{
"status": "affected",
"version": "1.0.0.2.000",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "MQAP-7628",
"vendor": "MoreQuick",
"versions": [
{
"status": "affected",
"version": "1.0.0.2.000",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "AP522",
"vendor": "Unknown",
"versions": [
{
"status": "affected",
"version": "1.0.0.2.014",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "AP7628",
"vendor": "Unknown",
"versions": [
{
"status": "affected",
"version": "3.0.0.4.380",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "APG721B",
"vendor": "Unknown",
"versions": [
{
"status": "affected",
"version": "19.0809",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "HC5661A",
"vendor": "Unknown",
"versions": [
{
"status": "affected",
"version": "3.0.0.4.380",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "HK300",
"vendor": "Unknown",
"versions": [
{
"status": "affected",
"version": "1.0.0.2.032",
"versionType": "custom"
}
]
},
{
"defaultStatus": "unknown",
"product": "MAP-N10",
"vendor": "Unknown",
"versions": [
{
"status": "affected",
"version": "1.0.0.2.044",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Jacob Baines of VulnCheck"
}
],
"datePublic": "2026-08-27T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels."
}
],
"impacts": [
{
"capecId": "CAPEC-94",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-94 Adversary in the Middle (AiTM)"
}
]
},
{
"capecId": "CAPEC-142",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-142 DNS Cache Poisoning"
}
]
},
{
"capecId": "CAPEC-248",
"descriptions": [
{
"lang": "en",
"value": "CAPEC-248 Command Injection"
}
]
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-506",
"description": "Embedded Malicious Code",
"lang": "en",
"type": "CWE"
},
{
"cweId": "CWE-300",
"description": "Channel Accessible by Non-Endpoint",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-27T10:39:14.386Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "VulnCheck Blog",
"tags": [
"technical-description",
"exploit"
],
"url": "http://vulncheck.com/blog/zbt-darklantern-speakingstone"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zbtlink-mqwrt-yunmgrd-cloud-c2-implant"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "Zbtlink MQWrt yunmgrd Cloud C2 Implant",
"x_generator": {
"engine": "Vulnogram 1.0.4"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-74232",
"datePublished": "2026-08-27T10:39:14.386Z",
"dateReserved": "2026-08-14T18:01:19.917Z",
"dateUpdated": "2026-08-27T14:49:10.575Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-73533 (GCVE-0-2026-73533)
Vulnerability from cvelistv5 – Published: 2026-08-13 16:00 – Updated: 2026-08-17 15:08 X_Known Exploited Vulnerability- CWE-506 - Embedded Malicious Code
| URL | Tags |
|---|---|
| https://wpmanageninja.com/security-incident-on-31… | technical-description |
| https://wordpress.org/plugins/ninja-tables/ | product |
| https://www.vulncheck.com/advisories/ninja-tables… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| WPManageNinja | Ninja Tables Pro |
Affected:
5.2.11
(semver)
cpe:2.3:a:wpmanageninja:ninja_tables:5.2.11:*:*:*:*:wordpress:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-73533",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-17T15:07:55.305156Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-17T15:08:31.482Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "Ninja Tables Pro",
"vendor": "WPManageNinja",
"versions": [
{
"status": "affected",
"version": "5.2.11",
"versionType": "semver"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:wpmanageninja:ninja_tables:5.2.11:*:*:*:*:wordpress:*:*",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"datePublic": "2026-08-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-506",
"description": "Embedded Malicious Code",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-14T16:52:30.724Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "WPManageNinja Security Incident",
"tags": [
"technical-description"
],
"url": "https://wpmanageninja.com/security-incident-on-31-july-2026/"
},
{
"name": "WP Plugin Page",
"tags": [
"product"
],
"url": "https://wordpress.org/plugins/ninja-tables/"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/ninja-tables-pro-embedded-malicious-code-via-tampered-plugin-build"
}
],
"source": {
"discovery": "INTERNAL"
},
"tags": [
"x_known-exploited-vulnerability"
],
"title": "Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-73533",
"datePublished": "2026-08-13T16:00:48.030Z",
"dateReserved": "2026-08-12T19:29:19.867Z",
"dateUpdated": "2026-08-17T15:08:31.482Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-73532 (GCVE-0-2026-73532)
Vulnerability from cvelistv5 – Published: 2026-08-13 16:01 – Updated: 2026-08-14 16:48 X_Known Exploited Vulnerability- CWE-506 - Embedded Malicious Code
| URL | Tags |
|---|---|
| https://wpmanageninja.com/security-incident-on-31… | technical-description |
| https://wordpress.org/plugins/fluentform/ | product |
| https://patchstack.com/database/wordpress/plugin/… | third-party-advisory |
| https://www.vulncheck.com/advisories/fluent-forms… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| WPManageNinja | Fluent Forms Pro |
Affected:
6.2.7
(semver)
|
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-73532",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-14T16:47:48.823900Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-14T16:48:08.232Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"product": "Fluent Forms Pro",
"vendor": "WPManageNinja",
"versions": [
{
"status": "affected",
"version": "6.2.7",
"versionType": "semver"
}
]
}
],
"datePublic": "2026-08-01T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-506",
"description": "Embedded Malicious Code",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-13T16:01:19.629Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "WPManageNinja Security Incident",
"tags": [
"technical-description"
],
"url": "https://wpmanageninja.com/security-incident-on-31-july-2026/"
},
{
"name": "WP Plugin Page",
"tags": [
"product"
],
"url": "https://wordpress.org/plugins/fluentform/"
},
{
"name": "Patchstack Advisory",
"tags": [
"third-party-advisory"
],
"url": "https://patchstack.com/database/wordpress/plugin/fluentformpro/vulnerability/wordpress-fluent-forms-pro-add-on-pack-plugin-6-2-7-6-2-7-remote-code-execution-vulnerability"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/fluent-forms-pro-embedded-malicious-code-via-tampered-plugin-build"
}
],
"source": {
"discovery": "INTERNAL"
},
"tags": [
"x_known-exploited-vulnerability"
],
"title": "Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-73532",
"datePublished": "2026-08-13T16:01:19.629Z",
"dateReserved": "2026-08-12T19:29:19.866Z",
"dateUpdated": "2026-08-14T16:48:08.232Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-67595 (GCVE-0-2026-67595)
Vulnerability from cvelistv5 – Published: 2026-07-29 21:33 – Updated: 2026-09-24 14:18 X_Open Source X_Known Exploited Vulnerability- CWE-506 - Embedded Malicious Code
| URL | Tags |
|---|---|
| https://github.com/webreinvent/vaahcms/pull/317 | issue-tracking |
| https://github.com/webreinvent/vaahcms/commit/8d7… | patch |
| https://www.vulncheck.com/advisories/vaahcms-mali… | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| webreinvent | vaahcms |
Affected:
2.0.0 , ≤ 2.3.4
(semver)
Unaffected: 8d7898f7a385a5fade1180a9b664ff158d873129 (git) cpe:2.3:a:webreinvent:vaahcms:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-67595",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-07-30T14:21:35.095590Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-07-30T15:17:56.308Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"defaultStatus": "affected",
"packageURL": "pkg:github/webreinvent/vaahcms",
"product": "vaahcms",
"repo": "https://github.com/webreinvent/vaahcms",
"vendor": "webreinvent",
"versions": [
{
"lessThanOrEqual": "2.3.4",
"status": "affected",
"version": "2.0.0",
"versionType": "semver"
},
{
"status": "unaffected",
"version": "8d7898f7a385a5fade1180a9b664ff158d873129",
"versionType": "git"
}
]
}
],
"cpeApplicability": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:webreinvent:vaahcms:*:*:*:*:*:*:*:*",
"versionEndIncluding": "2.3.4",
"versionStartIncluding": "2.0.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Ilhomjon Rustamov"
}
],
"datePublic": "2026-03-30T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"value": "VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, installs a password-field keylogger using MutationObserver to capture dynamically added inputs, scrapes WhatsApp Web DOM content, and accepts remote commands to redirect or overwrite the rendered page."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "PRESENT",
"attackVector": "NETWORK",
"baseScore": 9.2,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "HIGH",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 8.1,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-506",
"description": "Embedded Malicious Code",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-24T14:18:27.621Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "Pull Request",
"tags": [
"issue-tracking"
],
"url": "https://github.com/webreinvent/vaahcms/pull/317"
},
{
"name": "Patch Commit",
"tags": [
"patch"
],
"url": "https://github.com/webreinvent/vaahcms/commit/8d7898f7a385a5fade1180a9b664ff158d873129"
},
{
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/vaahcms-malicious-javascript-supply-chain-via-security-otp-blade-php"
}
],
"source": {
"discovery": "UNKNOWN"
},
"tags": [
"x_open-source",
"x_known-exploited-vulnerability"
],
"title": "VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-67595",
"datePublished": "2026-07-29T21:33:25.952Z",
"dateReserved": "2026-07-29T21:07:39.201Z",
"dateUpdated": "2026-09-24T14:18:27.621Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-66747 (GCVE-0-2026-66747)
Vulnerability from cvelistv5 – Published: 2026-08-05 10:50 – Updated: 2026-08-05 14:20- CWE-506 - Embedded Malicious Code
| URL | Tags |
|---|---|
| https://www.vulncheck.com/blog/zbt-endlessdoors | technical-descriptionexploit |
| https://www.zbtlink.com/pages/zbt-router-firmware… | product |
| https://github.com/ycsunjane/rctl | |
| https://www.vulncheck.com/advisories/zbt-endlessdoors | third-party-advisory |
| Vendor | Product | Version | |
|---|---|---|---|
| Zbtlink | CPE2801 Firmware |
Affected:
22.10.09
(custom)
cpe:2.3:o:zbtlink:cpe2801_firmware:*:*:*:*:*:*:*:* |
|
| Zbtlink | WE1026-5G-WD Firmware |
Affected:
21.04.07
(custom)
cpe:2.3:o:zbtlink:we1026-5g-wd_firmware:*:*:*:*:*:*:*:* |
|
| Zbtlink | WE1326 Firmware |
Affected:
22.02.18_1
(custom)
cpe:2.3:o:zbtlink:we1326_firmware:*:*:*:*:*:*:*:* |
|
| Zbtlink | WE2007 Firmware |
Affected:
23.08.12
(custom)
cpe:2.3:o:zbtlink:we2007_firmware:*:*:*:*:*:*:*:* |
|
| Zbtlink | WE2008-DSIM Firmware |
Affected:
23.08.11
(custom)
cpe:2.3:o:zbtlink:we2008-dsim_firmware:*:*:*:*:*:*:*:* |
|
| Zbtlink | WE2416 Firmware |
Affected:
21.03.22_1
(custom)
cpe:2.3:o:zbtlink:we2416_firmware:*:*:*:*:*:*:*:* |
|
| Zbtlink | WE3326 Firmware |
Affected:
20.09.30
(custom)
cpe:2.3:o:zbtlink:we3326_firmware:*:*:*:*:*:*:*:* |
|
| Zbtlink | WE5927 Firmware |
Affected:
22.08.10
(custom)
cpe:2.3:o:zbtlink:we5927_firmware:*:*:*:*:*:*:*:* |
|
| Zbtlink | WE5931 Firmware |
Affected:
22.05.31
(custom)
cpe:2.3:o:zbtlink:we5931_firmware:*:*:*:*:*:*:*:* |
|
| Zbtlink | WE5931AC Firmware |
Affected:
22.05.31
(custom)
cpe:2.3:o:zbtlink:we5931ac_firmware:*:*:*:*:*:*:*:* |
|
| Zbtlink | WE826-T3-DSIM Firmware |
Affected:
21.12.21
(custom)
cpe:2.3:o:zbtlink:we826-t3-dsim_firmware:*:*:*:*:*:*:*:* |
|
| Zbtlink | WG108 Firmware |
Affected:
21.08.06_1
(custom)
cpe:2.3:o:zbtlink:wg108_firmware:*:*:*:*:*:*:*:* |
|
| Zbtlink | WG209 Firmware |
Affected:
21.07.28
(custom)
cpe:2.3:o:zbtlink:wg209_firmware:*:*:*:*:*:*:*:* |
|
| Zbtlink | WG259 Firmware |
Affected:
21.03.23
(custom)
cpe:2.3:o:zbtlink:wg259_firmware:*:*:*:*:*:*:*:* |
|
| Zbtlink | WG1602 Firmware |
Affected:
23.10.11
(custom)
cpe:2.3:o:zbtlink:wg1602_firmware:*:*:*:*:*:*:*:* |
|
| Zbtlink | WG1608-DSIM Firmware |
Affected:
23.03.16
(custom)
cpe:2.3:o:zbtlink:wg1608-dsim_firmware:*:*:*:*:*:*:*:* |
|
| Zbtlink | WG2105 Firmware |
Affected:
22.05.30
(custom)
cpe:2.3:o:zbtlink:wg2105_firmware:*:*:*:*:*:*:*:* |
|
| Zbtlink | WG2107 Firmware |
Affected:
22.09.08
(custom)
cpe:2.3:o:zbtlink:wg2107_firmware:*:*:*:*:*:*:*:* |
|
| Zbtlink | WG3526 Firmware |
Affected:
22.11.01
(custom)
cpe:2.3:o:zbtlink:wg3526_firmware:*:*:*:*:*:*:*:* |
|
| Zbtlink | ZBT-Z8102AX-2SIM Firmware |
Affected:
7.6.7.2-25.0814_114432
(custom)
cpe:2.3:o:zbtlink:z8102ax_firmware:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-66747",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-05T14:19:25.533200Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T14:20:12.478Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:o:zbtlink:cpe2801_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"MIPS",
"ARM"
],
"product": "CPE2801 Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "22.10.09",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:zbtlink:we1026-5g-wd_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"MIPS",
"ARM"
],
"product": "WE1026-5G-WD Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "21.04.07",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:zbtlink:we1326_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"MIPS",
"ARM"
],
"product": "WE1326 Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "22.02.18_1",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:zbtlink:we2007_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"MIPS",
"ARM"
],
"product": "WE2007 Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "23.08.12",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:zbtlink:we2008-dsim_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"MIPS",
"ARM"
],
"product": "WE2008-DSIM Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "23.08.11",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:zbtlink:we2416_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"MIPS",
"ARM"
],
"product": "WE2416 Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "21.03.22_1",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:zbtlink:we3326_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"MIPS",
"ARM"
],
"product": "WE3326 Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "20.09.30",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:zbtlink:we5927_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"MIPS",
"ARM"
],
"product": "WE5927 Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "22.08.10",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:zbtlink:we5931_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"MIPS",
"ARM"
],
"product": "WE5931 Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "22.05.31",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:zbtlink:we5931ac_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"MIPS",
"ARM"
],
"product": "WE5931AC Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "22.05.31",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:zbtlink:we826-t3-dsim_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"MIPS",
"ARM"
],
"product": "WE826-T3-DSIM Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "21.12.21",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:zbtlink:wg108_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"MIPS",
"ARM"
],
"product": "WG108 Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "21.08.06_1",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:zbtlink:wg209_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"MIPS",
"ARM"
],
"product": "WG209 Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "21.07.28",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:zbtlink:wg259_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"MIPS",
"ARM"
],
"product": "WG259 Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "21.03.23",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:zbtlink:wg1602_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"MIPS",
"ARM"
],
"product": "WG1602 Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "23.10.11",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:zbtlink:wg1608-dsim_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"MIPS",
"ARM"
],
"product": "WG1608-DSIM Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "23.03.16",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:zbtlink:wg2105_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"MIPS",
"ARM"
],
"product": "WG2105 Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "22.05.30",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:zbtlink:wg2107_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"MIPS",
"ARM"
],
"product": "WG2107 Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "22.09.08",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:zbtlink:wg3526_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"MIPS",
"ARM"
],
"product": "WG3526 Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "22.11.01",
"versionType": "custom"
}
]
},
{
"cpes": [
"cpe:2.3:o:zbtlink:z8102ax_firmware:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unaffected",
"platforms": [
"ARM"
],
"product": "ZBT-Z8102AX-2SIM Firmware",
"vendor": "Zbtlink",
"versions": [
{
"status": "affected",
"version": "7.6.7.2-25.0814_114432",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "Jacob Baines of VulnCheck"
}
],
"datePublic": "2026-08-05T00:00:00.000Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "\u003cp\u003eZbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel\u0027s [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.\u003c/p\u003e"
}
],
"value": "Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel\u0027s [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root."
}
],
"metrics": [
{
"cvssV4_0": {
"Automatable": "NOT_DEFINED",
"Recovery": "NOT_DEFINED",
"Safety": "NOT_DEFINED",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"attackVector": "NETWORK",
"baseScore": 9.3,
"baseSeverity": "CRITICAL",
"exploitMaturity": "NOT_DEFINED",
"privilegesRequired": "NONE",
"providerUrgency": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"subConfidentialityImpact": "NONE",
"subIntegrityImpact": "NONE",
"userInteraction": "NONE",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
"version": "4.0",
"vulnAvailabilityImpact": "HIGH",
"vulnConfidentialityImpact": "HIGH",
"vulnIntegrityImpact": "HIGH",
"vulnerabilityResponseEffort": "NOT_DEFINED"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
},
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 9.8,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-506",
"description": "CWE-506 Embedded Malicious Code",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-05T10:55:20.206Z",
"orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"shortName": "VulnCheck"
},
"references": [
{
"name": "VulnCheck Research Blog",
"tags": [
"technical-description",
"exploit"
],
"url": "https://www.vulncheck.com/blog/zbt-endlessdoors"
},
{
"name": "Vendor Firmware Download Page",
"tags": [
"product"
],
"url": "https://www.zbtlink.com/pages/zbt-router-firmware-download"
},
{
"name": "Upstream Open Source rctl",
"url": "https://github.com/ycsunjane/rctl"
},
{
"name": "VulnCheck Advisory",
"tags": [
"third-party-advisory"
],
"url": "https://www.vulncheck.com/advisories/zbt-endlessdoors"
}
],
"source": {
"discovery": "UNKNOWN"
},
"title": "ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant",
"x_generator": {
"engine": "vulncheck"
}
}
},
"cveMetadata": {
"assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
"assignerShortName": "VulnCheck",
"cveId": "CVE-2026-66747",
"datePublished": "2026-08-05T10:50:45.576Z",
"dateReserved": "2026-07-27T16:27:47.648Z",
"dateUpdated": "2026-08-05T14:20:12.478Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation
Remove the malicious code and start an effort to ensure that no more malicious code exists. This may require a detailed review of all code, as it is possible to hide a serious attack in only one or two lines of code. These lines may be located almost anywhere in an application and may have been intentionally obfuscated by the attacker.
CAPEC-442: Infected Software
An adversary adds malicious logic, often in the form of a computer virus, to otherwise benign software. This logic is often hidden from the user of the software and works behind the scenes to achieve negative impacts. Many times, the malicious logic is inserted into empty space between legitimate code, and is then called when the software is executed. This pattern of attack focuses on software already fielded and used in operation as opposed to software that is still under development and part of the supply chain.
CAPEC-448: Embed Virus into DLL
An adversary tampers with a DLL and embeds a computer virus into gaps between legitimate machine instructions. These gaps may be the result of compiler optimizations that pad memory blocks for performance gains. The embedded virus then attempts to infect any machine which interfaces with the product, and possibly steal private data or eavesdrop.
CAPEC-636: Hiding Malicious Data or Code within Files
Files on various operating systems can have a complex format which allows for the storage of other data, in addition to its contents. Often this is metadata about the file, such as a cached thumbnail for an image file. Unless utilities are invoked in a particular way, this data is not visible during the normal use of the file. It is possible for an attacker to store malicious data or code using these facilities, which would be difficult to discover.