Louis Dion-Marcil

2 exploits Active since Jun 2025
CVE-2025-2171 WRITEUP HIGH WRITEUP
Aviatrix Controller <7.1.4208-8.0.0 - DoS
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN
CVE-2025-2172 WRITEUP MEDIUM WRITEUP
Aviatrix Controller <7.1.4208-8.0.0 - Command Injection
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenames