GreyNoise uncovers a stealth campaign exploiting ASUS routers, enabling persistent backdoor access via CVE-2023-39780 and unpatched techniques. Learn how attackers evade detection, how GreyNoise discovered it with AI-powered tooling, and what defenders need to know.
A vulnerability, which was classified as critical, was found in oretnom23 Online Pet Shop We App 1.0. Affected is an unknown function of the file /pet_shop/classes/Master.php?f=delete_order. The manipulation of the argument ID leads to sql injection.
This vulnerability is traded as CVE-2022-40933. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
A vulnerability has been found in oretnom23 Online Pet Shop We App 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /pet_shop/classes/Master.php?f=delete_sub_category. The manipulation of the argument ID leads to sql injection.
This vulnerability is known as CVE-2022-40934. The attack can be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in oretnom23 Online Pet Shop We App 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /pet_shop/classes/Master.php?f=delete_category. The manipulation of the argument ID leads to sql injection.
This vulnerability is handled as CVE-2022-40935. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability, which was classified as critical, was found in OTFCC 617837b. Affected is an unknown function of the file /release-x64/otfccdump+0x6adb1e. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2022-35037. Access to the local network is required for this attack to succeed. There is no exploit available.
A vulnerability has been found in OTFCC 617837b and classified as critical. Affected by this vulnerability is an unknown functionality of the file /release-x64/otfccdump+0x6b064d. The manipulation leads to out-of-bounds write.
This vulnerability is known as CVE-2022-35038. The attack can be launched remotely. There is no exploit available.
A vulnerability was found in OTFCC 617837b and classified as critical. Affected by this issue is some unknown functionality of the file /release-x64/otfccdump+0x6e20a0. The manipulation leads to out-of-bounds write.
This vulnerability is handled as CVE-2022-35039. The attack may be launched remotely. There is no exploit available.
A vulnerability has been found in Facebook WhatsApp on iOS/Android and classified as critical. This vulnerability affects unknown code of the component Video Call Handler. The manipulation leads to heap-based buffer overflow.
This vulnerability was named CVE-2022-36934. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in 10-Strike Network Inventory Explorer 9.3. It has been rated as critical. Affected by this issue is some unknown functionality of the component Add Computers Handler. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2022-38573. Access to the local network is required for this attack to succeed. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in HashiCorp Consul up to 1.11.8/1.12.4/1.13.1. This issue affects some unknown processing of the component Name Handler. The manipulation leads to missing authorization.
The identification of this vulnerability is CVE-2021-41803. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Crestron AirMedia 4.3.1.39 on Windows and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to insecure inherited permissions.
This vulnerability is handled as CVE-2022-40298. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.