Fullhan Microelectronics AJL30PG0803 IP Camera
Unauthenticated blind OS command injection via the custom SYSTEM protocol
CVSS 8.8ReservedCVE work, vulnerability research, and security-focused writeups across web, browser, and device security.
Unauthenticated blind OS command injection via the custom SYSTEM protocol
CVSS 8.8ReservedMissing authorization to plugin administration endpoints affecting cache, meta-tag, and contact-form settings
CVSS 7.6PublishedAuthenticated low-privileged users can create draft posts by bypassing role checks on the drafts endpoint
CVSS 4.3PublishedAuthenticated users can execute arbitrary Ruby code through select_eval custom field command input
CVSS 8.8PublishedStored XSS by injecting HTML in draft titles that is rendered in the admin drafts listing
CVSS 8.7PublishedServer-side template injection through the settings test_email action (ERB evaluated in email context)
CVSS 6.6PublishedAuthenticated SQL injection via crafted slug values in post create/edit flows
CVSS 7.1PublishedStored XSS via unsanitized cama_contact_form before_html content in contact-form editing
CVSS 8.7PublishedUnauthenticated access to admin-gated AJAX dispatch endpoints via header/path bypass
CVSS 9.8PublishedUnauthenticated persistent remote code execution via crafted install request payload
CVSS 9.8PublishedUnauthenticated PHP object injection through a crafted maxsite_comuser cookie value
CVSS 9.8PublishedSix assigned CVEs covering unauthenticated PSIA access, plaintext credential exposure, exposed snapshots, blind command execution, default Telnet, and plaintext Wi-Fi credentials.
Security review of Camaleon CMS 2.9.1 covering broken access control, stored XSS, authenticated RCE, SQL injection, and SSTI-to-RCE findings.
Browser extension research and tooling for identifying official Kosovo government domains and reducing phishing risk.
Not public yet, to be disclosed.