Endpunktsicherheit

🟠 CVE-2026-27559: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-27559: High Schwachstelle

A low-privileged remote attacker can exploit a command injection vulnerability in the /api/status/data endpoint by sending a crafted GET request...

18. Sep. 2026 Keine Kommentare
🟠 CVE-2026-27558: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-27558: High Schwachstelle

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/ajax_remove_uploaded_iodd_files endpoint using operator credentials allowing execu...

18. Sep. 2026 Keine Kommentare
🟠 CVE-2026-27556: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-27556: High Schwachstelle

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using a valid operator cookie...

18. Sep. 2026 Keine Kommentare
🟠 CVE-2026-27555: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-27555: High Schwachstelle

A low-privileged remote attacker can exploit a local file inclusion vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using a valid user cookie...

18. Sep. 2026 Keine Kommentare
🟠 CVE-2026-27554: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-27554: High Schwachstelle

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/save_iodd_parameters endpoint using operator credentials allowing execution of...

18. Sep. 2026 Keine Kommentare
🟠 CVE-2026-27551: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-27551: High Schwachstelle

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/parameterManage endpoint using user credentials allowing execution of...

18. Sep. 2026 Keine Kommentare
🟠 CVE-2026-27549: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-27549: High Schwachstelle

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/attached_devices_tab/do_upload endpoint using operator credentials allowing execution of...

18. Sep. 2026 Keine Kommentare
🟠 CVE-2026-27548: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-27548: High Schwachstelle

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_port_info endpoint using user or operator credentials allowing...

18. Sep. 2026 Keine Kommentare
🟠 CVE-2026-27547: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-27547: High Schwachstelle

A low-privileged remote attacker can exploit a command injection vulnerability in the /index.php/ajax/get_iodd_menu_info endpoint using valid user or operator credentials...

18. Sep. 2026 Keine Kommentare
BambooToken Malware Uses MQTT to Control Windows and Linux Systems ENDPUNKTSICHERHEIT

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a...

17. Sep. 2026 Keine Kommentare