Public exploit code also completes the Next.js ImageResponse path from attacker-controlled rendering input to native server execution.
The PKCS#11 TA makes the driver path reachable from a normal-world client.
OP-TEE Core, the secure-world operating system used by embedded and mobile platforms, particularly builds using NXP CAAM; SE050 and Versal were listed as possibly affected, and follow-up review identified a HiSilicon HPRE path.
Normal-world-triggered corruption of TEE-kernel stack or heap metadata
Input accepted from a normal-world client crosses into secure-world kernel memory, and follow-up review found that the first repair did not cover another backend path.
An attacker-controlled normal-world client can submit oversized RSA, DSA, DH, or ECC attributes through a reachable Trusted Application such as the PKCS#11 TA.
On NXP CAAM, an oversized ECC value is right-aligned before its allocated buffer after inconsistent sizing passes Core validation.
A September 28 follow-up identified analogous fixed-slot writes in HiSilicon HPRE, but that proposed repair closed on October 2 without merging.
Stack or heap corruption is established; repeatable control of secure-world kernel execution is not.
Encoding one character prevents the API authentication rule from matching the endpoint path.
Cisco Catalyst SD-WAN Manager, the management and orchestration component for Cisco SD-WAN deployments.
Unauthenticated API access with administrator privileges
This is an actively exploited failure of the administrative boundary around an enterprise SD-WAN control plane.
Any unauthenticated caller who can reach the Manager API can attempt the bypass.
The crafted URI misses the authentication rule and receives administrator-level API access.
Cisco confirms active exploitation and has published fixed releases.
Cisco does not publish the underlying patch diff; these conclusions rely on its current remediation and lifecycle documentation.
The demonstrated stack reaches execve through sharp and the official non-PIE Node.js Linux build.
Next.js applications using Node.js ImageResponse from next/og to generate server-side images.
Unauthenticated code execution in the Next.js server context
Public exploit material closes the execution chain on a specified stack instead of leaving the consequence at native-parser corruption; only routes that feed attacker-controlled values to ImageResponse are exposed.
An attacker first needs a public route that renders attacker-influenced content, attributes, or styles through next/og ImageResponse.
Satori emits the value unescaped into SVG, sharp's native renderer is corrupted, and the published ROP chain invokes execve in the server process.
The vendor advisory identifies a fixed Next.js version for the affected ImageResponse path.
The first two questions concern artifact acceptance and revocation mechanisms that this source-level dependency fix does not use; they are therefore recorded as unknown rather than treated as automatically complete.
MikroTik RouterOS, the operating system used by MikroTik routers and network appliances.
The CNA material describes one unauthenticated HTTP request body triggering an integer underflow and root code execution on a reachable WebFig service.
MikroTik's public changelog did not list the reported 7.24 release when checked, so we cannot establish that the announced fix is shipping from that vendor material.
WatchGuard Fireware OS on Firebox network-security appliances providing Access Portal and Mobile VPN with SSL services.
The caller still needs valid SAML credentials, but those credentials may be assigned only to the Access Portal.
A crafted login request selects Mobile VPN with SSL without the authorization check for that function.
WatchGuard lists fixed release ranges.
Xiaomi Router AX3000T, a consumer Wi-Fi 6 mesh router running MiWiFi/XiaoQiang firmware.
The firmware-global mesh key authenticates an arbitrary peer to cab_meshd, which discloses enough material to derive a valid administrator login response.
On a factory-reset RD03v2, malicious mesh initialization fields are evaluated by a root shell.
Public code and hardware testing validate the administrator takeover and uid-0 execution paths.
Wikipedia for Android, the Wikimedia Foundation's encyclopedia application on Android devices.
The app accepts an attacker hostname ending in wikipedia.org and repeats the suffix mistake when deciding where to send CentralAuth cookies.
Those cookies permit authenticated Wikimedia API access as the victim.
The maintainer tested a correction, but the advisory does not identify a fixed application version.
Zephyr RTOS devices built with the native DNS resolver and affected networking code.
A PTR record returned for an A or AAAA query is accepted as NET_AF_LOCAL, and its name length becomes the address-copy length.
The result is an out-of-bounds copy, but we do not know whether it permits controlled corruption or execution on a shipping device.
The upstream change blocks the type mismatch, but affected and fixed release boundaries remain unestablished in the public record.
Thales SConnect, browser-to-native middleware used by electronic-identity, signing and financial-authentication products on Windows workstations.
A failed RSA operation leaves attacker-influenced data in an uninitialized verification buffer, bypassing the origin token and both package-signature layers.
The researcher demonstrated the path in Edge with an unsigned message-box DLL.
WatchGuard Endpoint Security protection software and its PSKMAD kernel driver on Windows workstations and servers.
Missing authentication in PSKMAD.sys lets a non-administrator bypass the driver's handshake and issue privileged memory-read commands.
WatchGuard identifies a fixed Windows protection build.
Divi Membership by Divi Engine, a membership and registration plugin for WordPress websites.
One registration handler trusts serialized form metadata that selects the Administrator role.
A separate PayPal callback accepts an unsigned encoded user ID and sets that user's authentication cookie.
Published records identify corrected releases for both paths.
Digi Accelerated Linux, the embedded operating system used across Digi cellular routers, gateways, console servers, USB device servers and industrial connectivity products.
A crafted POST reaches an operating-system command sink through the DAL OS web-administration interface; packet delivery on the adjacent network is required.
Digi has published corrected DAL OS releases for the affected gateway and device-server family.
Netcore NAP930, a Wi-Fi 6 business access point running OpenWrt-derived embedded firmware.
The network_tools CGI evaluates the sid value before checking the session, so closing its quoted value appends a root shell command.
The published request was validated against the original firmware filesystem under emulation.
OpenWA, a self-hosted WhatsApp API gateway that links WhatsApp sessions to server-side automation and integrations.
Sending media to the linked WhatsApp number is enough to reach the default-enabled fetch path.
Sender-controlled media metadata selects the destination, including internal and link-local addresses, although the response body remains blind.
OpenWA 0.24.0 restricts these media fetches to WhatsApp hosts.
Vibe-Trading, a self-hosted LLM trading agent and FastAPI service commonly deployed in a Linux container.
Leaving API_AUTH_KEY unset disables authentication on the documented port 8899 deployment.
A caller can then control an agent session and reach shell or dynamic-module tools running as uid 0.
The project advisories include HTTP reproduction steps and a runtime uid-0 probe.
ConvertX, a self-hosted online file-conversion service normally deployed as a Linux container.
ConvertX passed uploaded recipe files to ebook-convert, which treats them as executable Python.
Authentication is required by default, while ALLOW_UNAUTHENTICATED deployments expose a cheaper route.
The upstream fix rejects both executable recipe extensions before invoking ebook-convert.
ASUS consumer routers running the vendor's embedded router firmware.
One path consumes uploaded management data as a format string; the other reaches active debug code that enables root Telnet access.
Because both paths require high-privilege router administration, the new capability is operating-system execution rather than new administrative access.
ASUS released firmware updates for the affected router series.
OP-TEE's normal-world-to-secure-world corruption family widened to another backend; no new universal Secure Boot bypass or signed-component revocation was established.
The recent RFCOMM change repairs a lock-order regression requiring a concurrent local connect and authentication; no new radio-only capability was established.
No recent event established a new physical-access capability or completed the open LUKS memory-acquisition chain.
Public exploit code completed the Next.js renderer-to-execution chain; RouterOS root execution remains provisional, and the Wikipedia Android session-theft path was demonstrated.
The same brief, every morning. One email a day, nothing else.
fullchain.sh follows the day’s disclosures from bug to shell — what each one enables, what it links to, and where the fix left the primitive in place.
Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.