Vulnerability Research & Published CVEs

Original security research from Solusec, disclosed responsibly and published so affected operators can fix what we found. Each entry links to its authoritative CVE record.

The findings below were identified during authorised testing and research by Solusec, assigned CVE identifiers through the appropriate numbering authority, and disclosed to the affected vendors before publication. They are shared for defensive and educational purposes.

Published CVEs

CVE-2024-48822 — Automatic Systems SlimLane — Privilege Escalation

Missing access control on FtpConfig.php lets an unauthenticated attacker read and set the device's FTP configuration. Tracked as CVE-2024-48822.

CVE-2024-48821 — Automatic Systems SlimLane — Stored XSS

Unsanitised FtpConfig.php fields persist a script payload that executes in operators' sessions. Tracked as CVE-2024-48821.

CVE-2024-48823 — Automatic Systems SlimLane — Local File Inclusion

The file parameter on PassageAutoServer.php reads files outside the web directory, unauthenticated. Tracked as CVE-2024-48823.

CVE-2024-48824 — Automatic Systems Monitoring Panel — Local File Inclusion

Racine and FileName on download-file.php combine into a path that escapes the web root. Tracked as CVE-2024-48824.

CVE-2024-46627 — BECN DATAGERRY v2.2 — Broken Access Control

User-settings REST endpoints lack authorisation, exposing any user's settings to read, write and delete. Tracked as CVE-2024-46627.

CVE-2024-45241 — CentralSquare CryWolf — Path Traversal

The rpt parameter on GeneralDocs.aspx discloses files outside the web root to unauthenticated attackers. Tracked as CVE-2024-45241.

What this says about how we test

Every issue here comes down to a small number of recurring root causes: endpoints that were never gated behind authorisation, input that was trusted when it reached the filesystem, and output that was rendered without encoding. These are exactly the classes of flaw manual, expert-led testing is built to surface. If you want testing to this standard on an authorised basis, the scoping conversation is free.

Found a vulnerability, or need testing that finds them?

We run coordinated disclosure for our own research and help vendors triage and fix what we report. If you need testing to this standard, the scoping conversation is free.