THREATOPS
THREAT OPSThreat News › [0day-rubbish] Leostream Connection Broker 9.1.37.0 two vulnerabilities (SQLi to root RCE, unauth SSRF)

[0day-rubbish] Leostream Connection Broker 9.1.37.0 two vulnerabilities (SQLi to root RCE, unauth SSRF)

medfulldisclosurePublished 2026-08-26

<p>Posted by disclosure via Fulldisclosure on Aug 26</p>0day Rubbish Research Team is publicly disclosing two vulnerabilities in Leostream Connection Broker 9.1.37.0.<br /> <br /> Vulnerability 1 — Authenticated SQL injection to webshell to root RCE (CVSS 9.1, <br /> CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, CWE-89)<br /> <br /> call_back.pl?action=user concatenates the unsigned _where paramet

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://seclists.org/fulldisclosure/2026/Aug/96