Aether-0

2 exploits Active since Dec 2024
CVE-2024-12986 NOMISEC HIGH WORKING POC
Draytek Vigor300b Firmware < 1.5.1.5 - Command Injection
A vulnerability, which was classified as critical, has been found in DrayTek Vigor2960 and Vigor300B 1.5.1.3/1.5.1.4. This issue affects some unknown processing of the file /cgi-bin/mainfunction.cgi/apmcfgupptim of the component Web Management Interface. The manipulation of the argument session leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.1.5 is able to address this issue. It is recommended to upgrade the affected component.
1 stars
CVSS 7.3
CVE-2025-55575 NOMISEC CRITICAL WORKING POC
SMM Panel 3.1 - SQL Injection
SQL Injection vulnerability in SMM Panel 3.1 allowing remote attackers to gain sensitive information via a crafted HTTP request with action=service_detail.
CVSS 9.8