Vulnerability Research

Our team discovers and responsibly discloses critical vulnerabilities in widely-deployed software, helping protect millions of systems worldwide.

15+

CVEs Published

8

Critical Findings

10+

Vendors Notified

1M+

Systems Protected

Published CVEs

CVE-2023-36845CriticalCVSS 9.82023
Juniper Networks Junos OS

Description

A PHP environment variable manipulation vulnerability in the J-Web component of Juniper Networks Junos OS allows an unauthenticated, network-based attacker to achieve remote code execution. The flaw exists in the way J-Web handles PHP environment variables, enabling attackers to execute arbitrary commands on affected devices.

Impact

Affects all Juniper SRX and EX series devices running vulnerable Junos OS versions with J-Web enabled. Widely exploited in the wild following disclosure.
CVE-2022-24990CriticalCVSS 9.82022
TerraMaster NAS

Description

An information disclosure vulnerability in the TerraMaster NAS API allows unauthenticated attackers to retrieve sensitive information including admin password hashes, leading to full device compromise and remote code execution.

Impact

Affects TerraMaster NAS devices worldwide. Combined with other flaws, enables complete takeover of network-attached storage devices containing sensitive data.
CVE-2022-46907HighCVSS 7.52022
Apache JSPWiki

Description

A cross-site scripting (XSS) vulnerability in Apache JSPWiki allows authenticated attackers to inject and execute arbitrary JavaScript in the context of other users' browsers. The flaw exists in the wiki page rendering engine.

Impact

Affects Apache JSPWiki deployments, enabling session hijacking, data theft, and privilege escalation through crafted wiki content.
CVE-2022-44877CriticalCVSS 9.82022
CentOS Web Panel (CWP7)

Description

An unauthenticated remote code execution vulnerability in CentOS Web Panel (CWP) due to improper input sanitization in the login page. The vulnerability allows OS command injection via the login parameter.

Impact

Affects all CentOS Web Panel installations. Actively exploited in the wild, enabling attackers to gain root access to web hosting servers managing multiple domains.
CVE-2024-XXXXXHighCVSS 7.82024
MAMP Server

Description

Multiple security vulnerabilities discovered in MAMP Server, a popular local development environment for macOS and Windows. The flaws include privilege escalation and arbitrary file access via the MAMP PRO interface.

Impact

Affects developers using MAMP for local development, potentially exposing development environments and credentials to local attackers.

Responsible Disclosure

We follow a coordinated disclosure process, working with vendors to ensure patches are available before public disclosure. If you believe you have found a vulnerability in our infrastructure, please contact security@octagon.net.