Public Security Advisories

Proof of Possession.

Coordinated vulnerability disclosures from Argus. Findings, impact, and remediation, published in good faith.

17
Advisories
3
Critical
10
High
2026
Latest

Disclosed

12
  • CRITICAL Fixed

    OpenBSD - Remote Kernel PAP Authentication Bypass

    sppp_pap_input uses attacker-controlled length fields directly as bcmp comparison length, allowing zero-length authentication bypass.

    OpenBSD / OpenBSD#auth#kernel#ppp#pppoe
  • HIGH Disclosed

    IDOR in Report Test — Low-Privilege User Can Access Any User's Dashboard Reports

    The report.test trapper endpoint allows an authenticated low-privilege user to supply an arbitrary userid in the request body. The server creates a real session for that user, renders their dashboard as a PDF, and emails it to the attacker — with no check that the requested viewer identity matches the authenticated caller.

    Zabbix / Zabbix Server#idor#access-control
  • CRITICAL Won't Fix

    SQL Injection via OAuth2 Token Refresh Response

    Zabbix server takes access_token and refresh_token values directly from an external OAuth server's HTTP response and interpolates them into a SQL UPDATE with no escaping. Stacked queries are enabled, giving an attacker who controls the token endpoint arbitrary SQL execution against the Zabbix database.

    Zabbix / Zabbix Server#sqli#oauth
  • HIGH Disclosed

    SSH Connection Reuse Authentication-Context Bypass

    SSH connection reuse matching in libcurl does not verify SSH authentication context.

  • MEDIUM Won't Fix

    MFA Bypass via Federated Login Paths

    Zabbix MFA enforcement is bypassed when logging in via HTTP Basic Auth or SAML SSO paths, which create fully active sessions without triggering the MFA challenge.

  • CRITICAL Disclosed

    Stack Buffer Overflow in ASP Handler

    An unchecked copy length derived from parsed network input causes a stack out-of-bounds write in the wlscan ASP handler.

    CVE-2026-6822, CVE-2026-6259Inhand Networks / 5G Modem#binary
  • MEDIUM Disclosed

    Race Condition in Temporary File Handling

    A non-atomic stat/unlink/fopen sequence on a fixed path in /var/tmp is exploitable via symlink substitution.

    CVE-2026-6822, CVE-2026-6259Inhand Networks / 5G Modem#binary
  • HIGH Disclosed

    Signedness Error in Network Read Path

    Error sentinel values from web_read are propagated as unsigned size arguments to f_write, enabling oversized memory operations.

    CVE-2026-6822, CVE-2026-6259Inhand Networks / 5G Modem#binary
  • HIGH Disclosed

    Path Traversal in File Handler

    Attacker-controlled filename input reaches fopen and unlink calls without canonicalization or directory confinement.

    CVE-2026-6822, CVE-2026-6259Inhand Networks / 5G Modem#binary
  • HIGH Disclosed

    OS Command Injection via Web Interface

    User-controlled CGI parameters and request-derived buffers are embedded into shell command strings and executed without sanitization.

    CVE-2026-6822, CVE-2026-6259Inhand Networks / 5G Modem#binary
  • HIGH Disclosed

    Hardcoded Default Credentials

    A hardcoded default admin password literal is embedded in the binary and used in authentication comparisons.

    CVE-2026-6822, CVE-2026-6259Inhand Networks / 5G Modem#binary
  • MEDIUM Disclosed

    Sensitive Data Exposure in Logs

    Captive portal credentials are written to syslog in plaintext on authentication failure.

    CVE-2026-6822, CVE-2026-6259Inhand Networks / 5G Modem#binary

Under Embargo

5