Win3Zz

#11921de 55,077
23.9CVSS total
Vulnerabilidades · 3
Média
1
Alta
1
Crítica
1
PT-2026-6803
10
2026-01-31
Beyondtrust · Beyondtrust Remote Support · CVE-2026-1731
**Nome do Software Vulnerável e Versões Afetadas** BeyondTrust Remote Support versões anteriores a 25.3.2 BeyondTrust Privileged Remote Access versões anteriores a 25.1.1 **Descrição** Uma falha de injeção de comando do sistema operacional de pré-autenticação existe no BeyondTrust Remote Support e Privileged Remote Access. Este problema permite que um invasor remoto não autenticado execute comandos arbitrários do sistema operacional no contexto do usuário do site ao enviar solicitações especialmente elaboradas. A falha está enraizada no script Bash `thin-scc-wrapper`, que manipula incorretamente a variável `remoteVersion` durante as negociações cliente-servidor através do endpoint WebSocket `/nw`. A exploração requer um cabeçalho HTTP `X-Ns-Company` válido que corresponda à configuração do sistema alvo. Aproximadamente 11.000 instâncias desses produtos estão expostas à internet, sendo cerca de 8.500 implantações locais. Este problema tem sido explorado ativamente em campanhas de ransomware, onde invasores o utilizaram para implantar ferramentas de monitoramento remoto, como o SimpleHelp, e utilizar o PowerShell para enumeração do Active Directory. **Recomendações** Atualize o BeyondTrust Remote Support para a versão 25.3.2 ou aplique a correção BT26-02-RS. Atualize o BeyondTrust Privileged Remote Access para a versão 25.1.1 ou aplique a correção BT26-02-PRA. Como mitigação temporária, restrinja o acesso ao endpoint WebSocket `/nw` para minimizar o risco de exploração.
PT-2023-5865
7.8
2023-10-01
Milesight · Milesight Ur32L · CVE-2023-43261
**Name of the Vulnerable Software and Affected Versions** Milesight UR5X, UR32L, UR32, UR35, UR41 versions prior to 35.3.0.7 **Description** An information disclosure issue exists in Milesight routers. This allows attackers to access sensitive router components. Reports indicate that approximately 19,000 Milesight routers with exposed APIs have been identified, with at least 572 publicly accessible without authentication. This has been exploited in real-world attacks, primarily in Europe (Sweden, Italy, Belgium), to send SMS spam containing phishing links. The vulnerability allows attackers to view system logs, locate, and compromise administrator passwords. These compromised credentials can then be used to abuse the router's SMS API to send malicious messages. The API can be exploited due to misconfigurations or the presence of the vulnerability. The attackers are leveraging the SMS notification feature commonly found in industrial routers to send spam messages. Some malicious URLs include JavaScript that checks for mobile access before delivering harmful content. Connections to a Telegram bot named GroozaBot have also been observed. The `SMS API` is being abused in these attacks. **Recommendations** Update Milesight UR5X, UR32L, UR32, UR35, and UR41 routers to version 35.3.0.7 or later. Restrict access to the `SMS API` to prevent unauthorized use. Ensure proper configuration of the SMS notification feature to prevent abuse. Monitor system logs for suspicious activity. Change default administrator passwords to strong, unique credentials. Disable the SMS notification feature if it is not required.