Overview
- CODESYS
- CODESYS Control RTE (SL)
Description
Statistics
- 1 Post
Fediverse
#OT #Advisory VDE-2025-100
CODESYS Control - Invalid type usage in visualization
A vulnerability in the CODESYS Control runtime system's CmpVisuServer component allows attackers to cause a denial-of-service (DoS) by sending special request to the CODESYS Web- or remote Target Visu. The issue is triggered by an internal read access using a pointer of wrong type.
#CVE CVE-2025-41738
https://certvde.com/en/advisories/vde-2025-100/
#CSAF https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2025/advisory2025-10_vde-2025-100.json
Overview
Description
Statistics
- 1 Post
Overview
- Unisoc (Shanghai) Technologies Co., Ltd.
- T8100/T9100/T8200/T8300
Description
Statistics
- 1 Post
Fediverse
🚨 CVE-2025-61610 (HIGH): Unisoc T8100/T9100/T8200/T8300 chipsets (Android 13-16) are at risk of remote DoS via NR modem crash (improper input validation). No authentication needed. Monitor for patches & apply network controls. Details: https://radar.offseq.com/threat/cve-2025-61610-cwe-20-improper-input-validation-in-8e20d7e2 #OffSeq #Unisoc #Infosec
Overview
- CODESYS
- CODESYS PLCHandler
Description
Statistics
- 1 Post
Fediverse
#OT #Advisory VDE-2025-099
CODESYS Control - Linux/QNX SysSocket flaw
A vulnerability has been identified in the CODESYS Control runtime system, which includes an abstraction layer designed to ensure compatibility across different operating systems. This layer is used both by affected CODESYS products and by applications running on the PLC.
#CVE CVE-2025-41739
https://certvde.com/en/advisories/vde-2025-099/
#CSAF https://codesys.csaf-tp.certvde.com/.well-known/csaf/white/2025/advisory2025-09_vde-2025-099.json
Overview
- Apache Software Foundation
- Apache Struts
- org.apache.struts:struts2-core
Description
Statistics
- 1 Post
Overview
- expressjs
- express
Description
Statistics
- 4 Posts
Overview
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 3 Posts
Fediverse
Alas, I don't have a physical Android 14 device with headset client already enabled. Only smartwatches, wearables, and cars support acting as Bluetooth headsets. I'm not about to drop $70,000 on a car for a blog post.
I examined the patch and wrote a proof-of-concept:
https://worthdoingbadly.com/bluetooth/
My proof-of-concept is available at https://github.com/zhuowei/blueshrimp; it gets "fault addr 0x4141414141414141" on the Android Automotive emulator... once you accept the pairing request.
Overview
- Microsoft
- Windows 11 Version 25H2
Description
Statistics
- 1 Post
Fediverse
🚨 Alleged Sale of Exploit Code for CVE-2025-60709
https://darkwebinformer.com/alleged-sale-of-exploit-code-for-cve-2025-60709/