[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[FD] Security advisory: Pre-authentication RCE (SQL injection) in XPressEntry 3.7.7454 (Telaeris Inc)
- To: fulldisclosure@xxxxxxxxxxxx
- Subject: [FD] Security advisory: Pre-authentication RCE (SQL injection) in XPressEntry 3.7.7454 (Telaeris Inc)
- From: disclosure via Fulldisclosure <fulldisclosure@xxxxxxxxxxxx>
- Date: Tue, 18 Aug 2026 06:06:02 +0000
0day Rubbish Research Team is publicly disclosing a vulnerability in
XPressEntry 3.7.7454 (Telaeris Inc). The research is published and a
proof-of-concept is available.
Pre-authentication RCE (SQL injection) (CVSS 9.8, pre-authentication)
Telaeris XPressEntry 3.7.7454 runs its main HTTP API without authentication
when RequireReaderCredentials is False, which is the default. The
SaveVerifyActivity handler concatenates the sNotes parameter into an INSERT
statement with no escaping. On a SQL Server backend with a sysadmin application
account, an unauthenticated attacker uses a COMMIT-breakout payload to enable
xp_cmdshell and execute arbitrary commands as LocalSystem. Dynamically verified.
Impact: Full compromise of the physical access-control and emergency-mustering
system as LocalSystem. The attacker can alter badge records, forge or block
entry events, and take over facility-security infrastructure.
Advisory:
https://0day-rubbish.com/blog/telaeris-xpressentry-unauth-sqli-xpcmdshell-rce
PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish
Vendor has been notified. CVE ID is pending.
--
0day Rubbish Research Team
https://0day-rubbish.com
_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: https://seclists.org/fulldisclosure/