EXODUS BLOG


Month: June 2022

TP-Link WR940N/WR941ND Uninitialized Pointer Vulnerability

JUNE 23, 2022
EIP-9ad27c94 An uninitialized pointer vulnerability exists within TP-Link’s WR940N and WR941ND SOHO router devices specifically during the processing of UPnP/SOAP SUBSCRIBE requests. Successful exploitation allow local unauthenticated attackers the ability to execute arbitrary code...
Read More

Mitel Web Management Interface Buffer Overflow Vulnerability

JUNE 9, 2022
EIP-c4542e4d A stack-based buffer overflow vulnerability exists within multiple Mitel product web management interfaces, including the 3300 Controller and MiVoice Business product lines. Improper handling of the ‘Lang’ query parameter allows remote unauthenticated attackers...
Read More

SalesAgility SuiteCRM ‘export’ Request SQL Injection Vulnerability

JUNE 9, 2022
EIP-0f5d2d7f A SQL injection vulnerability exists within SalesAgility SuiteCRM within the processing of the ‘uid’ parameter within the ‘export’ functionality. Successful exploitation allows remote unauthenticated attackers to ultimately execute arbitrary code. Vulnerability Identifiers Exodus...
Read More