THREAT OPS › Threat News › Security advisory: multiple vulnerabilities including Authenticated RCE (property injection), Hardcoded credentials, Pre-authentication root RCE in CatDV Server 10.7.8 (Square Box Systems)
Security advisory: multiple vulnerabilities including Authenticated RCE (property injection), Hardcoded credentials, Pre-authentication root RCE in CatDV Server 10.7.8 (Square Box Systems)
<p>Posted by disclosure via Fulldisclosure on Aug 06</p>0day Rubbish Research Team is publicly disclosing 3 vulnerabilities in CatDV Server 10.7.8 (Square Box Systems). The <br /> research is published and a proof-of-concept is available.<br /> <br /> Vulnerability 1: Pre-authentication root RCE (CVSS 9.8, pre-authentication)<br /> <br /> A three-defect chain turns any deployment into an unauthent
MITRE ATT&CK techniques
Original source: https://seclists.org/fulldisclosure/2026/Aug/6