Security advisory: Pre-authentication RCE (SQL injection) in XPressEntry 3.7.7454 (Telaeris Inc)
Full Disclosuremailing list archivesFrom: disclosure via Fulldisclosure <fulldis 2026-8-18 06:17:52 Author: seclists.org(查看原文) 阅读量:4 收藏

fulldisclosure logo

Full Disclosure mailing list archives


From: disclosure via Fulldisclosure <fulldisclosure () seclists org>
Date: Tue, 18 Aug 2026 06:06:02 +0000

0day Rubbish Research Team is publicly disclosing a vulnerability in XPressEntry 3.7.7454 (Telaeris Inc). The research 
is published and a proof-of-concept is available.

Pre-authentication RCE (SQL injection) (CVSS 9.8, pre-authentication)

Telaeris XPressEntry 3.7.7454 runs its main HTTP API without authentication when RequireReaderCredentials is False, 
which is the default. The SaveVerifyActivity handler concatenates the sNotes parameter into an INSERT statement with no 
escaping. On a SQL Server backend with a sysadmin application account, an unauthenticated attacker uses a 
COMMIT-breakout payload to enable xp_cmdshell and execute arbitrary commands as LocalSystem. Dynamically verified.

Impact: Full compromise of the physical access-control and emergency-mustering system as LocalSystem. The attacker can 
alter badge records, forge or block entry events, and take over facility-security infrastructure.

Advisory: https://0day-rubbish.com/blog/telaeris-xpressentry-unauth-sqli-xpcmdshell-rce

PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish

Vendor has been notified. CVE ID is pending.

-- 
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/


Current thread:

  • Security advisory: Pre-authentication RCE (SQL injection) in XPressEntry 3.7.7454 (Telaeris Inc) disclosure via Fulldisclosure (Aug 17)

文章来源: https://seclists.org/fulldisclosure/2026/Aug/67
如有侵权请联系:admin#unsafe.sh