Overview
- Progress Software
- MOVEit Automation
Description
Statistics
- 1 Post
Bluesky
Overview
- CODESYS
- Control RTE (SL)
Description
Statistics
- 1 Post
Fediverse
#OT #Advisory VDE-2026-005
ifm: Multiple Vulnerabilities in CR3171
The Firmware installed on the CR3171 is impacted by various CODESYS vulnerabilities.
#CVE CVE-2025-41659, CVE-2025-41691, CVE-2025-41658
https://certvde.com/en/advisories/vde-2026-005/
#CSAF https://ifm.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-005.json
Overview
- CODESYS
- Control RTE (SL)
Description
Statistics
- 1 Post
Fediverse
#OT #Advisory VDE-2026-005
ifm: Multiple Vulnerabilities in CR3171
The Firmware installed on the CR3171 is impacted by various CODESYS vulnerabilities.
#CVE CVE-2025-41659, CVE-2025-41691, CVE-2025-41658
https://certvde.com/en/advisories/vde-2026-005/
#CSAF https://ifm.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-005.json
Overview
- CODESYS
- Runtime Toolkit
Description
Statistics
- 1 Post
Fediverse
#OT #Advisory VDE-2026-005
ifm: Multiple Vulnerabilities in CR3171
The Firmware installed on the CR3171 is impacted by various CODESYS vulnerabilities.
#CVE CVE-2025-41659, CVE-2025-41691, CVE-2025-41658
https://certvde.com/en/advisories/vde-2026-005/
#CSAF https://ifm.csaf-tp.certvde.com/.well-known/csaf/white/2026/vde-2026-005.json
Overview
- Crafter Software
- Crafter CMS
Description
Statistics
- 1 Post
Fediverse
The Crafter CMS Groovy sandbox has been patched three times. CVE-2021-23259, CVE-2022-40635, CVE-2025-6384.
Our team went back in anyway and found 14 distinct RCE bypass techniques in v5.0.0: AST Transformations, SpelExpressionParser, GroovyShell, Template Engines, XStream, BeanShell, Jakarta EL, Commons Exec, Object Factories, MBeans, and more.
The sandbox wasn't broken in one place. It was porous.
CVE-2026-1770 (PTT-2025-022). Full PoC: https://pentest-tools.com/research
Overview
- CrafterCMS
- CrafterCMS
- Studio
Description
Statistics
- 1 Post
Fediverse
The Crafter CMS Groovy sandbox has been patched three times. CVE-2021-23259, CVE-2022-40635, CVE-2025-6384.
Our team went back in anyway and found 14 distinct RCE bypass techniques in v5.0.0: AST Transformations, SpelExpressionParser, GroovyShell, Template Engines, XStream, BeanShell, Jakarta EL, Commons Exec, Object Factories, MBeans, and more.
The sandbox wasn't broken in one place. It was porous.
CVE-2026-1770 (PTT-2025-022). Full PoC: https://pentest-tools.com/research
Overview
- CrafterCMS
- CrafterCMS
- Studio
Description
Statistics
- 1 Post
Fediverse
The Crafter CMS Groovy sandbox has been patched three times. CVE-2021-23259, CVE-2022-40635, CVE-2025-6384.
Our team went back in anyway and found 14 distinct RCE bypass techniques in v5.0.0: AST Transformations, SpelExpressionParser, GroovyShell, Template Engines, XStream, BeanShell, Jakarta EL, Commons Exec, Object Factories, MBeans, and more.
The sandbox wasn't broken in one place. It was porous.
CVE-2026-1770 (PTT-2025-022). Full PoC: https://pentest-tools.com/research
Overview
- Crafter Software
- Crafter CMS
Description
Statistics
- 1 Post
Fediverse
The Crafter CMS Groovy sandbox has been patched three times. CVE-2021-23259, CVE-2022-40635, CVE-2025-6384.
Our team went back in anyway and found 14 distinct RCE bypass techniques in v5.0.0: AST Transformations, SpelExpressionParser, GroovyShell, Template Engines, XStream, BeanShell, Jakarta EL, Commons Exec, Object Factories, MBeans, and more.
The sandbox wasn't broken in one place. It was porous.
CVE-2026-1770 (PTT-2025-022). Full PoC: https://pentest-tools.com/research