CyberHighConfirmedDeveloping
10.0
Critical pre-auth RCE vulnerability identified in OpenWrt DHCPv6 service
The Hacker News·2 days ago
A remote code execution vulnerability in Gitea allows users with repository write access to execute arbitrary shell commands as the service account. The exploit is particularly severe because default configurations permit public registration, enabling unauthenticated attackers to gain the necessary write permissions. A public proof-of-concept is available, increasing the risk of immediate exploitation.