THREAT OPS › Threat News › [0day-rubbish] Leostream Connection Broker 9.1.37.0 two vulnerabilities (SQLi to root RCE, unauth SSRF)
[0day-rubbish] Leostream Connection Broker 9.1.37.0 two vulnerabilities (SQLi to root RCE, unauth SSRF)
<p>Posted by disclosure via Fulldisclosure on Aug 26</p>0day Rubbish Research Team is publicly disclosing two vulnerabilities in Leostream Connection Broker 9.1.37.0.<br /> <br /> Vulnerability 1 — Authenticated SQL injection to webshell to root RCE (CVSS 9.1, <br /> CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, CWE-89)<br /> <br /> call_back.pl?action=user concatenates the unsigned _where paramet
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
Indicators of compromise
- 9.1.37.0ipv4
Original source: https://seclists.org/fulldisclosure/2026/Aug/96