The findings below were identified during authorised testing and research by Solusec, assigned CVE identifiers through the appropriate numbering authority, and disclosed to the affected vendors before publication. They are shared for defensive and educational purposes.
Published CVEs
CVE-2024-48822 — Automatic Systems SlimLane — Privilege Escalation
Missing access control on FtpConfig.php lets an unauthenticated attacker read and set the device's FTP configuration. Tracked as CVE-2024-48822.
CVE-2024-48821 — Automatic Systems SlimLane — Stored XSS
Unsanitised FtpConfig.php fields persist a script payload that executes in operators' sessions. Tracked as CVE-2024-48821.
CVE-2024-48823 — Automatic Systems SlimLane — Local File Inclusion
The file parameter on PassageAutoServer.php reads files outside the web directory, unauthenticated. Tracked as CVE-2024-48823.
CVE-2024-48824 — Automatic Systems Monitoring Panel — Local File Inclusion
Racine and FileName on download-file.php combine into a path that escapes the web root. Tracked as CVE-2024-48824.
CVE-2024-46627 — BECN DATAGERRY v2.2 — Broken Access Control
User-settings REST endpoints lack authorisation, exposing any user's settings to read, write and delete. Tracked as CVE-2024-46627.
CVE-2024-45241 — CentralSquare CryWolf — Path Traversal
The rpt parameter on GeneralDocs.aspx discloses files outside the web root to unauthenticated attackers. Tracked as CVE-2024-45241.
What this says about how we test
Every issue here comes down to a small number of recurring root causes: endpoints that were never gated behind authorisation, input that was trusted when it reached the filesystem, and output that was rendered without encoding. These are exactly the classes of flaw manual, expert-led testing is built to surface. If you want testing to this standard on an authorised basis, the scoping conversation is free.
Solusec
Typically replies within one business day
Had an incident, or need a pen test at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day