Common Weakness Enumeration

CWE-506

Allowed-with-Review

Embedded Malicious Code

Abstraction: Class · Status: Incomplete

The product contains code that appears to be malicious in nature.

553 vulnerabilities reference this CWE, most recent first.

CVE-2026-97230 (GCVE-0-2026-97230)

Vulnerability from cvelistv5 – Published: 2026-09-24 22:36 – Updated: 2026-09-25 16:11
VLAI
Title
IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL
Summary
IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly. The impact is that arbitrary code can be invoked as the user, without a dropped script being saved on the affected host. The releases have no test scripts nor build hooks. The intention may have been to trigger the payload after installation. The dropper script is in lib/Crypt/SelfCertificate/sample/cert.pem. This is similar to CVE-2026-95831 for the module Crypt::SelfCertificate. The SHA-256 digests of the files are ba24ee8ec3b7f47f65bed62e16fb413ace50653cf44bd8ea90914390922831e0 IO-Socket-SSL-SelfCertificate-1.00.tar.gz 821d38830e5eb8607738421c25ac25f59fff02a6ab67daa32fbd020429454dac IO-Socket-SSL-SelfCertificate-1.00/lib/IO/Socket/SSL/SelfCertificate/sample/cert.pem d483cb7b23b7271cb11cf242bff4a2e1c02df0b9525eb0429abeea8961c399d5 IO-Socket-SSL-SelfCertificate-1.00-upload.tar.gz
SSVC
Exploitation: none Automatable: yes Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-25 16:11 UTC
CWE
  • CWE-506 - Embedded Malicious Code
Impacted products
Vendor Product Version
Affected: 1.00 (custom)
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "NETWORK",
              "availabilityImpact": "HIGH",
              "baseScore": 9.8,
              "baseSeverity": "CRITICAL",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "privilegesRequired": "NONE",
              "scope": "UNCHANGED",
              "userInteraction": "NONE",
              "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2026-97230",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-25T16:11:04.730543Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-25T16:11:11.028Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "collectionURL": "https://cpan.org/modules",
          "defaultStatus": "unaffected",
          "modules": [
            "IO::Socket::SSL::SelfCertificate"
          ],
          "packageName": "IO-Socket-SSL-SelfCertificate",
          "packageURL": "pkg:cpan/IO-Socket-SSL-SelfCertificate",
          "programFiles": [
            "lib/IO/Socket/SSL/SelfCertificate.pm",
            "lib/IO/Socket/SSL/SelfCertificate/sample/cert.pem"
          ],
          "versions": [
            {
              "status": "affected",
              "version": "1.00",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL.\n\nThe generate_certificate runs a Python script saved as a certificate file.  The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly.\n\nThe impact is that arbitrary code can be invoked as the user, without a dropped script being saved on the affected host.\n\nThe releases have no test scripts nor build hooks.  The intention may have been to trigger the payload after installation.\n\nThe dropper script is in lib/Crypt/SelfCertificate/sample/cert.pem.\n\nThis is similar to CVE-2026-95831 for the module Crypt::SelfCertificate.\n\nThe SHA-256 digests of the files are\n\n    ba24ee8ec3b7f47f65bed62e16fb413ace50653cf44bd8ea90914390922831e0  IO-Socket-SSL-SelfCertificate-1.00.tar.gz\n    821d38830e5eb8607738421c25ac25f59fff02a6ab67daa32fbd020429454dac  IO-Socket-SSL-SelfCertificate-1.00/lib/IO/Socket/SSL/SelfCertificate/sample/cert.pem\n\n    d483cb7b23b7271cb11cf242bff4a2e1c02df0b9525eb0429abeea8961c399d5  IO-Socket-SSL-SelfCertificate-1.00-upload.tar.gz"
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-253",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-253 Remote Code Inclusion"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-506",
              "description": "CWE-506 Embedded Malicious Code",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-24T22:36:50.882Z",
        "orgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
        "shortName": "CPANSec"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://www.nntp.perl.org/group/perl.cpan.testers.discuss/2026/09/msg4756.html"
        },
        {
          "tags": [
            "related"
          ],
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-95831"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "value": "Systems on which the affected package was installed should be considered potentially compromised and investigated accordingly."
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "title": "IO::Socket::SSL::SelfCertificate versions 1.00 for Perl contains malware which executes Python code from an obfuscated URL",
      "x_generator": {
        "engine": "cpansec-cna-tool 0.1"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
    "assignerShortName": "CPANSec",
    "cveId": "CVE-2026-97230",
    "datePublished": "2026-09-24T22:36:50.882Z",
    "dateReserved": "2026-09-24T10:09:37.672Z",
    "dateUpdated": "2026-09-25T16:11:11.028Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-95831 (GCVE-0-2026-95831)

Vulnerability from cvelistv5 – Published: 2026-09-22 18:21 – Updated: 2026-09-23 16:09
VLAI
Title
Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL
Summary
Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL. The generate_certificate runs a Python script saved as a certificate file. The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly. The impact is that arbitrary code can be invoked as the user, without a dropped script being saved on the affected host. The releases have no test scripts nor build hooks. The intention may have been to trigger the payload after installation. For version 1.01, the dropper script is in lib/Crypt/SelfCertificate/sample/validate.p12. For version 1.05, the dropper script is in lib/Crypt/SelfCertificate/sample/cert7.pem. The SHA-256 digests of the files are fbff21f45ff748365062a5e36fb2d72558cad82a507a6f357f320b4fcdf07760 Crypt-SelfCertificate-1.01.tar.gz 27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/validate.p12 9fdfa7d69b034b77d4510cda567e8da1e486ca81c7daaadc5732a45c41d71991 Crypt-SelfCertificate-1.05.tar.gz 27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/cert7.pem
SSVC
Exploitation: none Automatable: no Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-09-22 20:13 UTC
CWE
  • CWE-506 - Embedded Malicious Code
Impacted products
Vendor Product Version
Affected: 1.01 , ≤ 1.05 (custom)
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2026-09-23T16:09:02.987Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "url": "http://www.openwall.com/lists/oss-security/2026/09/22/21"
          },
          {
            "url": "http://www.openwall.com/lists/oss-security/2026/09/23/2"
          },
          {
            "url": "http://www.openwall.com/lists/oss-security/2026/09/23/3"
          }
        ],
        "title": "CVE Program Container"
      },
      {
        "metrics": [
          {
            "cvssV3_1": {
              "attackComplexity": "LOW",
              "attackVector": "LOCAL",
              "availabilityImpact": "HIGH",
              "baseScore": 7.8,
              "baseSeverity": "HIGH",
              "confidentialityImpact": "HIGH",
              "integrityImpact": "HIGH",
              "privilegesRequired": "NONE",
              "scope": "UNCHANGED",
              "userInteraction": "REQUIRED",
              "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
              "version": "3.1"
            }
          },
          {
            "other": {
              "content": {
                "id": "CVE-2026-95831",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-22T20:13:35.298576Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-22T20:13:37.851Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "collectionURL": "https://cpan.org/modules",
          "defaultStatus": "unaffected",
          "modules": [
            "Crypt::SelfCertificate"
          ],
          "packageName": "Crypt-SelfCertificate",
          "packageURL": "pkg:cpan/Crypt-SelfCertificate",
          "programFiles": [
            "lib/Crypt/SelfCertificate.pm",
            "lib/Crypt/SelfCertificate/sample/validate.p12",
            "lib/Crypt/SelfCertificate/sample/cert7.pem"
          ],
          "versions": [
            {
              "lessThanOrEqual": "1.05",
              "status": "affected",
              "version": "1.01",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL.\n\nThe generate_certificate runs a Python script saved as a certificate file.  The pyhton script attempts to retrieve code from a hardcoded http URL that is obfuscated with base64 encoding and run the response body directly.\n\nThe impact is that arbitrary code can be invoked as the user, without a dropped script being saved on the affected host.\n\nThe releases have no test scripts nor build hooks.  The intention may have been to trigger the payload after installation.\n\nFor version 1.01, the dropper script is in lib/Crypt/SelfCertificate/sample/validate.p12.\n\nFor version 1.05, the dropper script is in lib/Crypt/SelfCertificate/sample/cert7.pem.\n\nThe SHA-256 digests of the files are\n\n    fbff21f45ff748365062a5e36fb2d72558cad82a507a6f357f320b4fcdf07760 Crypt-SelfCertificate-1.01.tar.gz\n    27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/validate.p12\n\n    9fdfa7d69b034b77d4510cda567e8da1e486ca81c7daaadc5732a45c41d71991 Crypt-SelfCertificate-1.05.tar.gz\n    27b2d2d3174ad771474fff2521f5084ec231e9218ea8c832515aef1cbd5897bc lib/Crypt/SelfCertificate/sample/cert7.pem"
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-253",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-253 Remote Code Inclusion"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-506",
              "description": "CWE-506 Embedded Malicious Code",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-22T18:21:23.728Z",
        "orgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
        "shortName": "CPANSec"
      },
      "references": [
        {
          "tags": [
            "vendor-advisory"
          ],
          "url": "https://www.nntp.perl.org/group/perl.cpan.testers.discuss/2026/09/msg4754.html"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "value": "Systems on which the affected package was installed should be considered potentially compromised and investigated accordingly."
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "timeline": [
        {
          "lang": "en",
          "time": "2026-09-15T00:00:00.000Z",
          "value": "Crypt::SelfCertificate version 1.00 uploaded to CPAN"
        },
        {
          "lang": "en",
          "time": "2026-09-17T00:00:00.000Z",
          "value": "Crypt::SelfCertificate version 1.01 uploaded to CPAN"
        },
        {
          "lang": "en",
          "time": "2026-09-22T00:00:00.000Z",
          "value": "Crypt::SelfCertificate version 1.05 uploaded to CPAN"
        },
        {
          "lang": "en",
          "time": "2026-09-22T00:00:00.000Z",
          "value": "Malware identified by CPANSec scanning"
        }
      ],
      "title": "Crypt::SelfCertificate versions from 1.01 through 1.05 for Perl contains malware which executes Python code from an obfuscated URL",
      "x_generator": {
        "engine": "cpansec-cna-tool 0.1"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "9b29abf9-4ab0-4765-b253-1875cd9b441e",
    "assignerShortName": "CPANSec",
    "cveId": "CVE-2026-95831",
    "datePublished": "2026-09-22T18:21:23.728Z",
    "dateReserved": "2026-09-22T16:29:23.694Z",
    "dateUpdated": "2026-09-23T16:09:02.987Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-77651 (GCVE-0-2026-77651)

Vulnerability from cvelistv5 – Published: 2026-08-21 00:41 – Updated: 2026-08-21 13:17
VLAI
Summary
The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
SSVC
Exploitation: none Automatable: yes Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-21 13:17 UTC
CWE
  • CWE-506 - Embedded Malicious Code
Impacted products
Vendor Product Version
droundy arrayref Affected: 0.3.10 (semver)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-77651",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-21T13:17:41.622051Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-21T13:17:52.920Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "arrayref",
          "vendor": "droundy",
          "versions": [
            {
              "status": "affected",
              "version": "0.3.10",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-506",
              "description": "CWE-506 Embedded Malicious Code",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-21T00:41:36.099Z",
        "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "shortName": "mitre"
      },
      "references": [
        {
          "url": "https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref"
        },
        {
          "url": "https://github.com/rustsec/advisory-db/issues/3161"
        },
        {
          "url": "https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack"
        },
        {
          "url": "https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/"
        },
        {
          "url": "https://rustsec.org/advisories/RUSTSEC-2026-0260.html"
        }
      ],
      "x_generator": {
        "engine": "CVE-Request-form 0.0.1"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
    "assignerShortName": "mitre",
    "cveId": "CVE-2026-77651",
    "datePublished": "2026-08-21T00:41:36.099Z",
    "dateReserved": "2026-08-21T00:41:35.750Z",
    "dateUpdated": "2026-08-21T13:17:52.920Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-77650 (GCVE-0-2026-77650)

Vulnerability from cvelistv5 – Published: 2026-08-21 00:40 – Updated: 2026-08-21 13:20
VLAI
Summary
The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
SSVC
Exploitation: none Automatable: yes Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-21 13:18 UTC
CWE
  • CWE-506 - Embedded Malicious Code
Impacted products
Vendor Product Version
droundy append-only-vec Affected: 0.1.9 (semver)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-77650",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-21T13:18:56.634996Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-21T13:20:06.921Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "append-only-vec",
          "vendor": "droundy",
          "versions": [
            {
              "status": "affected",
              "version": "0.1.9",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-506",
              "description": "CWE-506 Embedded Malicious Code",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-21T00:40:26.467Z",
        "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "shortName": "mitre"
      },
      "references": [
        {
          "url": "https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref"
        },
        {
          "url": "https://github.com/rustsec/advisory-db/issues/3161"
        },
        {
          "url": "https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack"
        },
        {
          "url": "https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/"
        },
        {
          "url": "https://rustsec.org/advisories/RUSTSEC-2026-0262.html"
        }
      ],
      "x_generator": {
        "engine": "CVE-Request-form 0.0.1"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
    "assignerShortName": "mitre",
    "cveId": "CVE-2026-77650",
    "datePublished": "2026-08-21T00:40:26.467Z",
    "dateReserved": "2026-08-21T00:40:26.113Z",
    "dateUpdated": "2026-08-21T13:20:06.921Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-77649 (GCVE-0-2026-77649)

Vulnerability from cvelistv5 – Published: 2026-08-21 00:39 – Updated: 2026-08-21 13:25
VLAI
Summary
The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution.
SSVC
Exploitation: none Automatable: yes Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-21 13:25 UTC
CWE
  • CWE-506 - Embedded Malicious Code
Impacted products
Vendor Product Version
droundy internment Affected: 0.8.7 (semver)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-77649",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-21T13:25:28.760292Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-21T13:25:41.885Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "internment",
          "vendor": "droundy",
          "versions": [
            {
              "status": "affected",
              "version": "0.8.7",
              "versionType": "semver"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue dependency that registers with a command-and-control server to offer arbitrary code execution."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-506",
              "description": "CWE-506 Embedded Malicious Code",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-21T00:39:02.071Z",
        "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
        "shortName": "mitre"
      },
      "references": [
        {
          "url": "https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref"
        },
        {
          "url": "https://github.com/rustsec/advisory-db/issues/3161"
        },
        {
          "url": "https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack"
        },
        {
          "url": "https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/"
        },
        {
          "url": "https://rustsec.org/advisories/RUSTSEC-2026-0266.html"
        }
      ],
      "x_generator": {
        "engine": "CVE-Request-form 0.0.1"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca",
    "assignerShortName": "mitre",
    "cveId": "CVE-2026-77649",
    "datePublished": "2026-08-21T00:39:02.071Z",
    "dateReserved": "2026-08-21T00:39:01.558Z",
    "dateUpdated": "2026-08-21T13:25:41.885Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-74232 (GCVE-0-2026-74232)

Vulnerability from cvelistv5 – Published: 2026-08-27 10:39 – Updated: 2026-08-27 14:49
VLAI
Title
Zbtlink MQWrt yunmgrd Cloud C2 Implant
Summary
Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels.
SSVC
Exploitation: poc Automatable: yes Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-27 14:48 UTC
CWE
  • CWE-506 - Embedded Malicious Code
  • CWE-300 - Channel Accessible by Non-Endpoint
References
Date Public
2026-08-27 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-74232",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-27T14:48:59.362199Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-27T14:49:10.575Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unknown",
          "product": "L3_V2_8",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "3.0.0.4.528",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "WE826-T2",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "19.1101",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "ZBT-7628",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0.2.007",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "ZBT-ZBT7621",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0.3.001",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "MQAC-7620",
          "vendor": "MoreQuick",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0.2.000",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "MQAC-7620A",
          "vendor": "MoreQuick",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0.2.000",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "MQAP-7620",
          "vendor": "MoreQuick",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0.2.000",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "MQAP-7620A",
          "vendor": "MoreQuick",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0.2.000",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "MQAP-7628",
          "vendor": "MoreQuick",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0.2.000",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "AP522",
          "vendor": "Unknown",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0.2.014",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "AP7628",
          "vendor": "Unknown",
          "versions": [
            {
              "status": "affected",
              "version": "3.0.0.4.380",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "APG721B",
          "vendor": "Unknown",
          "versions": [
            {
              "status": "affected",
              "version": "19.0809",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "HC5661A",
          "vendor": "Unknown",
          "versions": [
            {
              "status": "affected",
              "version": "3.0.0.4.380",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "HK300",
          "vendor": "Unknown",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0.2.032",
              "versionType": "custom"
            }
          ]
        },
        {
          "defaultStatus": "unknown",
          "product": "MAP-N10",
          "vendor": "Unknown",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0.2.044",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Jacob Baines of VulnCheck"
        }
      ],
      "datePublic": "2026-08-27T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, AP522 firmware 1.0.0.2.014, AP7628 and HC5661A firmware 3.0.0.4.380, APG721B firmware 19.0809, HK300 firmware 1.0.0.2.032, and MAP-N10 firmware 1.0.0.2.044 ship a backdoor command-and-control implant (yunmgrd) reachable over an unauthenticated cleartext UDP channel to a hardcoded C2 server. A remote unauthenticated attacker on the network path can hijack the channel and execute arbitrary commands as root. The attacker can also modify DNS entries, exfiltrate PPPoE credentials, and open reverse SSH tunnels."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-94",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-94 Adversary in the Middle (AiTM)"
            }
          ]
        },
        {
          "capecId": "CAPEC-142",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-142 DNS Cache Poisoning"
            }
          ]
        },
        {
          "capecId": "CAPEC-248",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-248 Command Injection"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 9.3,
            "baseSeverity": "CRITICAL",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-506",
              "description": "Embedded Malicious Code",
              "lang": "en",
              "type": "CWE"
            },
            {
              "cweId": "CWE-300",
              "description": "Channel Accessible by Non-Endpoint",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-27T10:39:14.386Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "VulnCheck Blog",
          "tags": [
            "technical-description",
            "exploit"
          ],
          "url": "http://vulncheck.com/blog/zbt-darklantern-speakingstone"
        },
        {
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/zbtlink-mqwrt-yunmgrd-cloud-c2-implant"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "title": "Zbtlink MQWrt yunmgrd Cloud C2 Implant",
      "x_generator": {
        "engine": "Vulnogram 1.0.4"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-74232",
    "datePublished": "2026-08-27T10:39:14.386Z",
    "dateReserved": "2026-08-14T18:01:19.917Z",
    "dateUpdated": "2026-08-27T14:49:10.575Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-73533 (GCVE-0-2026-73533)

Vulnerability from cvelistv5 – Published: 2026-08-13 16:00 – Updated: 2026-08-17 15:08 X_Known Exploited Vulnerability
VLAI
Title
Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build
Summary
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.
SSVC
Exploitation: none Automatable: yes Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-17 15:07 UTC
CWE
  • CWE-506 - Embedded Malicious Code
Impacted products
Vendor Product Version
WPManageNinja Ninja Tables Pro Affected: 5.2.11 (semver)
    cpe:2.3:a:wpmanageninja:ninja_tables:5.2.11:*:*:*:*:wordpress:*:*
Create a notification for this product.
Date Public
2026-08-01 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-73533",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-17T15:07:55.305156Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-17T15:08:31.482Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "affected",
          "product": "Ninja Tables Pro",
          "vendor": "WPManageNinja",
          "versions": [
            {
              "status": "affected",
              "version": "5.2.11",
              "versionType": "semver"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:wpmanageninja:ninja_tables:5.2.11:*:*:*:*:wordpress:*:*",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "datePublic": "2026-08-01T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 9.3,
            "baseSeverity": "CRITICAL",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-506",
              "description": "Embedded Malicious Code",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-14T16:52:30.724Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "WPManageNinja Security Incident",
          "tags": [
            "technical-description"
          ],
          "url": "https://wpmanageninja.com/security-incident-on-31-july-2026/"
        },
        {
          "name": "WP Plugin Page",
          "tags": [
            "product"
          ],
          "url": "https://wordpress.org/plugins/ninja-tables/"
        },
        {
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/ninja-tables-pro-embedded-malicious-code-via-tampered-plugin-build"
        }
      ],
      "source": {
        "discovery": "INTERNAL"
      },
      "tags": [
        "x_known-exploited-vulnerability"
      ],
      "title": "Ninja Tables Pro 5.2.11 Embedded Malicious Code via Tampered Plugin Build",
      "x_generator": {
        "engine": "vulncheck"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-73533",
    "datePublished": "2026-08-13T16:00:48.030Z",
    "dateReserved": "2026-08-12T19:29:19.867Z",
    "dateUpdated": "2026-08-17T15:08:31.482Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-73532 (GCVE-0-2026-73532)

Vulnerability from cvelistv5 – Published: 2026-08-13 16:01 – Updated: 2026-08-14 16:48 X_Known Exploited Vulnerability
VLAI
Title
Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build
Summary
Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal.
SSVC
Exploitation: none Automatable: yes Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-14 16:47 UTC
CWE
  • CWE-506 - Embedded Malicious Code
Impacted products
Vendor Product Version
WPManageNinja Fluent Forms Pro Affected: 6.2.7 (semver)
Create a notification for this product.
Date Public
2026-08-01 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-73532",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-14T16:47:48.823900Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-14T16:48:08.232Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "affected",
          "product": "Fluent Forms Pro",
          "vendor": "WPManageNinja",
          "versions": [
            {
              "status": "affected",
              "version": "6.2.7",
              "versionType": "semver"
            }
          ]
        }
      ],
      "datePublic": "2026-08-01T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (libs/class-license-sync.php), loaded via a require_once directive added to fluentformpro.php, that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and uploads directories, installed a passwordless administrator account, and registered scheduled tasks that survived plugin removal."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 9.3,
            "baseSeverity": "CRITICAL",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-506",
              "description": "Embedded Malicious Code",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-13T16:01:19.629Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "WPManageNinja Security Incident",
          "tags": [
            "technical-description"
          ],
          "url": "https://wpmanageninja.com/security-incident-on-31-july-2026/"
        },
        {
          "name": "WP Plugin Page",
          "tags": [
            "product"
          ],
          "url": "https://wordpress.org/plugins/fluentform/"
        },
        {
          "name": "Patchstack Advisory",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://patchstack.com/database/wordpress/plugin/fluentformpro/vulnerability/wordpress-fluent-forms-pro-add-on-pack-plugin-6-2-7-6-2-7-remote-code-execution-vulnerability"
        },
        {
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/fluent-forms-pro-embedded-malicious-code-via-tampered-plugin-build"
        }
      ],
      "source": {
        "discovery": "INTERNAL"
      },
      "tags": [
        "x_known-exploited-vulnerability"
      ],
      "title": "Fluent Forms Pro 6.2.7 Embedded Malicious Code via Tampered Plugin Build",
      "x_generator": {
        "engine": "vulncheck"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-73532",
    "datePublished": "2026-08-13T16:01:19.629Z",
    "dateReserved": "2026-08-12T19:29:19.866Z",
    "dateUpdated": "2026-08-14T16:48:08.232Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-67595 (GCVE-0-2026-67595)

Vulnerability from cvelistv5 – Published: 2026-07-29 21:33 – Updated: 2026-09-24 14:18 X_Open Source X_Known Exploited Vulnerability
VLAI
Title
VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php
Summary
VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, installs a password-field keylogger using MutationObserver to capture dynamically added inputs, scrapes WhatsApp Web DOM content, and accepts remote commands to redirect or overwrite the rendered page.
SSVC
Exploitation: none Automatable: no Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-07-30 14:21 UTC
CWE
  • CWE-506 - Embedded Malicious Code
Impacted products
Vendor Product Version
webreinvent vaahcms Affected: 2.0.0 , ≤ 2.3.4 (semver)
Unaffected: 8d7898f7a385a5fade1180a9b664ff158d873129 (git)
    cpe:2.3:a:webreinvent:vaahcms:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-03-30 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-67595",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-07-30T14:21:35.095590Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-07-30T15:17:56.308Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "affected",
          "packageURL": "pkg:github/webreinvent/vaahcms",
          "product": "vaahcms",
          "repo": "https://github.com/webreinvent/vaahcms",
          "vendor": "webreinvent",
          "versions": [
            {
              "lessThanOrEqual": "2.3.4",
              "status": "affected",
              "version": "2.0.0",
              "versionType": "semver"
            },
            {
              "status": "unaffected",
              "version": "8d7898f7a385a5fade1180a9b664ff158d873129",
              "versionType": "git"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:a:webreinvent:vaahcms:*:*:*:*:*:*:*:*",
                  "versionEndIncluding": "2.3.4",
                  "versionStartIncluding": "2.0.0",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Ilhomjon Rustamov"
        }
      ],
      "datePublic": "2026-03-30T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "VaahCMS versions 2.0.0 through 2.3.4 contain a malicious obfuscated JavaScript payload embedded in the Blade template responsible for rendering security OTP emails, allowing remote attackers to execute unauthorized code in any browser that renders the affected email template with JavaScript enabled. The payload establishes a WebSocket connection to a hardcoded command-and-control endpoint, installs a password-field keylogger using MutationObserver to capture dynamically added inputs, scrapes WhatsApp Web DOM content, and accepts remote commands to redirect or overwrite the rendered page."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "PRESENT",
            "attackVector": "NETWORK",
            "baseScore": 9.2,
            "baseSeverity": "CRITICAL",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-506",
              "description": "Embedded Malicious Code",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-24T14:18:27.621Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "Pull Request",
          "tags": [
            "issue-tracking"
          ],
          "url": "https://github.com/webreinvent/vaahcms/pull/317"
        },
        {
          "name": "Patch Commit",
          "tags": [
            "patch"
          ],
          "url": "https://github.com/webreinvent/vaahcms/commit/8d7898f7a385a5fade1180a9b664ff158d873129"
        },
        {
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/vaahcms-malicious-javascript-supply-chain-via-security-otp-blade-php"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "tags": [
        "x_open-source",
        "x_known-exploited-vulnerability"
      ],
      "title": "VaahCMS 2.0.0 - 2.3.4 Malicious JavaScript Supply Chain via security-otp.blade.php",
      "x_generator": {
        "engine": "vulncheck"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-67595",
    "datePublished": "2026-07-29T21:33:25.952Z",
    "dateReserved": "2026-07-29T21:07:39.201Z",
    "dateUpdated": "2026-09-24T14:18:27.621Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

CVE-2026-66747 (GCVE-0-2026-66747)

Vulnerability from cvelistv5 – Published: 2026-08-05 10:50 – Updated: 2026-08-05 14:20
VLAI
Title
ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant
Summary
Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel's [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.
SSVC
Exploitation: poc Automatable: yes Technical Impact: total
CISA Coordinator · CISA-ADP (v2.0.3)
Decision recorded 2026-08-05 14:19 UTC
CWE
  • CWE-506 - Embedded Malicious Code
Impacted products
Vendor Product Version
Zbtlink CPE2801 Firmware Affected: 22.10.09 (custom)
    cpe:2.3:o:zbtlink:cpe2801_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Zbtlink WE1026-5G-WD Firmware Affected: 21.04.07 (custom)
    cpe:2.3:o:zbtlink:we1026-5g-wd_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Zbtlink WE1326 Firmware Affected: 22.02.18_1 (custom)
    cpe:2.3:o:zbtlink:we1326_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Zbtlink WE2007 Firmware Affected: 23.08.12 (custom)
    cpe:2.3:o:zbtlink:we2007_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Zbtlink WE2008-DSIM Firmware Affected: 23.08.11 (custom)
    cpe:2.3:o:zbtlink:we2008-dsim_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Zbtlink WE2416 Firmware Affected: 21.03.22_1 (custom)
    cpe:2.3:o:zbtlink:we2416_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Zbtlink WE3326 Firmware Affected: 20.09.30 (custom)
    cpe:2.3:o:zbtlink:we3326_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Zbtlink WE5927 Firmware Affected: 22.08.10 (custom)
    cpe:2.3:o:zbtlink:we5927_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Zbtlink WE5931 Firmware Affected: 22.05.31 (custom)
    cpe:2.3:o:zbtlink:we5931_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Zbtlink WE5931AC Firmware Affected: 22.05.31 (custom)
    cpe:2.3:o:zbtlink:we5931ac_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Zbtlink WE826-T3-DSIM Firmware Affected: 21.12.21 (custom)
    cpe:2.3:o:zbtlink:we826-t3-dsim_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Zbtlink WG108 Firmware Affected: 21.08.06_1 (custom)
    cpe:2.3:o:zbtlink:wg108_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Zbtlink WG209 Firmware Affected: 21.07.28 (custom)
    cpe:2.3:o:zbtlink:wg209_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Zbtlink WG259 Firmware Affected: 21.03.23 (custom)
    cpe:2.3:o:zbtlink:wg259_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Zbtlink WG1602 Firmware Affected: 23.10.11 (custom)
    cpe:2.3:o:zbtlink:wg1602_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Zbtlink WG1608-DSIM Firmware Affected: 23.03.16 (custom)
    cpe:2.3:o:zbtlink:wg1608-dsim_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Zbtlink WG2105 Firmware Affected: 22.05.30 (custom)
    cpe:2.3:o:zbtlink:wg2105_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Zbtlink WG2107 Firmware Affected: 22.09.08 (custom)
    cpe:2.3:o:zbtlink:wg2107_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Zbtlink WG3526 Firmware Affected: 22.11.01 (custom)
    cpe:2.3:o:zbtlink:wg3526_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Zbtlink ZBT-Z8102AX-2SIM Firmware Affected: 7.6.7.2-25.0814_114432 (custom)
    cpe:2.3:o:zbtlink:z8102ax_firmware:*:*:*:*:*:*:*:*
Create a notification for this product.
Date Public
2026-08-05 00:00
Show details on NVD website

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-66747",
                "options": [
                  {
                    "Exploitation": "poc"
                  },
                  {
                    "Automatable": "yes"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-08-05T14:19:25.533200Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-08-05T14:20:12.478Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:cpe2801_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "MIPS",
            "ARM"
          ],
          "product": "CPE2801 Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "22.10.09",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:we1026-5g-wd_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "MIPS",
            "ARM"
          ],
          "product": "WE1026-5G-WD Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "21.04.07",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:we1326_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "MIPS",
            "ARM"
          ],
          "product": "WE1326 Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "22.02.18_1",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:we2007_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "MIPS",
            "ARM"
          ],
          "product": "WE2007 Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "23.08.12",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:we2008-dsim_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "MIPS",
            "ARM"
          ],
          "product": "WE2008-DSIM Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "23.08.11",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:we2416_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "MIPS",
            "ARM"
          ],
          "product": "WE2416 Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "21.03.22_1",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:we3326_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "MIPS",
            "ARM"
          ],
          "product": "WE3326 Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "20.09.30",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:we5927_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "MIPS",
            "ARM"
          ],
          "product": "WE5927 Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "22.08.10",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:we5931_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "MIPS",
            "ARM"
          ],
          "product": "WE5931 Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "22.05.31",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:we5931ac_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "MIPS",
            "ARM"
          ],
          "product": "WE5931AC Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "22.05.31",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:we826-t3-dsim_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "MIPS",
            "ARM"
          ],
          "product": "WE826-T3-DSIM Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "21.12.21",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:wg108_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "MIPS",
            "ARM"
          ],
          "product": "WG108 Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "21.08.06_1",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:wg209_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "MIPS",
            "ARM"
          ],
          "product": "WG209 Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "21.07.28",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:wg259_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "MIPS",
            "ARM"
          ],
          "product": "WG259 Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "21.03.23",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:wg1602_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "MIPS",
            "ARM"
          ],
          "product": "WG1602 Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "23.10.11",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:wg1608-dsim_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "MIPS",
            "ARM"
          ],
          "product": "WG1608-DSIM Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "23.03.16",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:wg2105_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "MIPS",
            "ARM"
          ],
          "product": "WG2105 Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "22.05.30",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:wg2107_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "MIPS",
            "ARM"
          ],
          "product": "WG2107 Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "22.09.08",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:wg3526_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "MIPS",
            "ARM"
          ],
          "product": "WG3526 Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "22.11.01",
              "versionType": "custom"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:o:zbtlink:z8102ax_firmware:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "platforms": [
            "ARM"
          ],
          "product": "ZBT-Z8102AX-2SIM Firmware",
          "vendor": "Zbtlink",
          "versions": [
            {
              "status": "affected",
              "version": "7.6.7.2-25.0814_114432",
              "versionType": "custom"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Jacob Baines of VulnCheck"
        }
      ],
      "datePublic": "2026-08-05T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "\u003cp\u003eZbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel\u0027s [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root.\u003c/p\u003e"
            }
          ],
          "value": "Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the open-source ycsunjane/rctl tool built in as an OpenWrt package (librctl.so), started at boot and run as root under the process name kworker to blend in with the kernel\u0027s [kworker/*] threads. It opens no listening port; it phones home over cleartext TCP to a hardcoded command-and-control server (command channel 7000, interactive-shell callback 7001) with no authentication and no transport encryption, re-attempting contact roughly every 35 seconds. Its command handler passes any received string to popen() as uid=0, and a reserved rctlbash command returns an interactive root shell. Because the channel is unauthenticated and cleartext, control is not limited to whoever planted it: any party that answers at the C2 address, occupies the network path (DNS or route hijack), or acquires the hardcoded fallback domain obtains unauthenticated remote code execution as root."
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NOT_DEFINED",
            "Recovery": "NOT_DEFINED",
            "Safety": "NOT_DEFINED",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 9.3,
            "baseSeverity": "CRITICAL",
            "exploitMaturity": "NOT_DEFINED",
            "privilegesRequired": "NONE",
            "providerUrgency": "NOT_DEFINED",
            "subAvailabilityImpact": "NONE",
            "subConfidentialityImpact": "NONE",
            "subIntegrityImpact": "NONE",
            "userInteraction": "NONE",
            "valueDensity": "NOT_DEFINED",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
            "version": "4.0",
            "vulnAvailabilityImpact": "HIGH",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "NOT_DEFINED"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        },
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-506",
              "description": "CWE-506 Embedded Malicious Code",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-08-05T10:55:20.206Z",
        "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
        "shortName": "VulnCheck"
      },
      "references": [
        {
          "name": "VulnCheck Research Blog",
          "tags": [
            "technical-description",
            "exploit"
          ],
          "url": "https://www.vulncheck.com/blog/zbt-endlessdoors"
        },
        {
          "name": "Vendor Firmware Download Page",
          "tags": [
            "product"
          ],
          "url": "https://www.zbtlink.com/pages/zbt-router-firmware-download"
        },
        {
          "name": "Upstream Open Source rctl",
          "url": "https://github.com/ycsunjane/rctl"
        },
        {
          "name": "VulnCheck Advisory",
          "tags": [
            "third-party-advisory"
          ],
          "url": "https://www.vulncheck.com/advisories/zbt-endlessdoors"
        }
      ],
      "source": {
        "discovery": "UNKNOWN"
      },
      "title": "ENDLESSDOORS: Zbtlink Router rctl/kworker Phone-Home Root Implant",
      "x_generator": {
        "engine": "vulncheck"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10",
    "assignerShortName": "VulnCheck",
    "cveId": "CVE-2026-66747",
    "datePublished": "2026-08-05T10:50:45.576Z",
    "dateReserved": "2026-07-27T16:27:47.648Z",
    "dateUpdated": "2026-08-05T14:20:12.478Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}

Mitigation
Implementation Operation

Remove the malicious code and start an effort to ensure that no more malicious code exists. This may require a detailed review of all code, as it is possible to hide a serious attack in only one or two lines of code. These lines may be located almost anywhere in an application and may have been intentionally obfuscated by the attacker.

CAPEC-442: Infected Software

An adversary adds malicious logic, often in the form of a computer virus, to otherwise benign software. This logic is often hidden from the user of the software and works behind the scenes to achieve negative impacts. Many times, the malicious logic is inserted into empty space between legitimate code, and is then called when the software is executed. This pattern of attack focuses on software already fielded and used in operation as opposed to software that is still under development and part of the supply chain.

CAPEC-448: Embed Virus into DLL

An adversary tampers with a DLL and embeds a computer virus into gaps between legitimate machine instructions. These gaps may be the result of compiler optimizations that pad memory blocks for performance gains. The embedded virus then attempts to infect any machine which interfaces with the product, and possibly steal private data or eavesdrop.

CAPEC-636: Hiding Malicious Data or Code within Files

Files on various operating systems can have a complex format which allows for the storage of other data, in addition to its contents. Often this is metadata about the file, such as a cached thumbnail for an image file. Unless utilities are invoked in a particular way, this data is not visible during the normal use of the file. It is possible for an attacker to store malicious data or code using these facilities, which would be difficult to discover.