Cisco's security group Talos has just published several critical, until now unpatched industrial-router-related vulnerabilities from MC Technologies. A serious weakness is also available in the GoCast BGP tool. The vulnerabilities have been said to have been responsibly brought up by the vendors nearly eight months ago. No official patches have been released. Last month, Talos already published advisories about them; now, it followed through with a blog post today, pointing out that things stand still. One of the weaknesses was identified in the web interface of the MC LR industrial router from MC Technologies in version. Talos found four OS command-injection vulnerabilities with a high severity rating, where an authenticated attacker on the device can gain arbitrary command execution on the device. Attackers can send special HTTP requests for exploitation. MC Technologies is a firm based in Germany that specializes in IoT and Industry solutions, notified about these vulnerabilities in March and has not yet patched. Talos also discovered three critical vulnerabilities in GoCast, which is the open source management tool for BGP route advertisement. These depend on an OS command injection and present implications of unauthenticated attackers exploited. In specially crafted HTTP requests, arbitrary commands from the affected system can be performed. The reported vulnerabilities occurred in April to GoCast but are still unpatched. Continued patches to patch those vulnerabilities remain of significant concern as users of both MC Technologies' routers and GoCast face a potential threat. Thus, Talos is pushing on the concerned vendors so that they may be forced to release urgent patches for protection against probable cyber attacks that might exploit those flaws.
A recent security update for Veeam Backup & Replication addresses several vulnerabilities that could allow attackers to run malicious code or gain elevated privileges within enterp...
Google has released an emergency security update to address two newly identified zero-day vulnerabilities in the Chrome desktop browser that are reportedly being exploited in real-...
A critical security vulnerability has been identified in the open-source identity and access management platform ZITADEL. The flaw, tracked as CVE-2026-29191, is a Cross-Site Scrip...