使用开源大语言模型将安全通告与易受攻击的函数配对
作者:Trevor Dunlap, John Speed Meyers, Bradley Reaves, and William Enck.
译者:知道创宇404实验室翻译组
原文链接:https://www.enck.org/pubs/dunlap-dimva24.pdf
摘要
随着对开源软件依赖性的需求不断增加,管理这些依赖中的安全漏洞变得愈加复杂。当前最先进的工业工具通过代码的可达性分...
A significant post-authentication vulnerability affecting Four-Faith industrial routers has been actively exploited in the wild. Assigned as CVE-2024-12856, this flaw allows attackers to execute unauthenticated remote command injections by leveraging the routers’ default credentials. Details of the Exploitation The vulnerability impacts at least two Four-Faith router models—F3x24 and F3x36. It involves leveraging the /apply.cgi endpoint over HTTP by […]
The post Four-Faith Industrial Routers Vulnerability Exploited in the Wild to Gain Remote Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.