CyberHighConfirmedDeveloping
10.0
Critical pre-auth RCE vulnerability identified in OpenWrt DHCPv6 service
The Hacker News·2 days ago
A security flaw in Ruflo's Model Context Protocol (MCP) tools leaves 233 deployments exposed to unauthenticated shell command execution. This vulnerability enables attackers to exfiltrate LLM API keys, conversation history, and persistent memory via a single POST request on network-reachable instances.