[0day-rubbish] Server Technology PRO3X PDU 030600 port_mux listener program override to root command execution (7.2)
0day Rubbish disclosed authenticated root command execution in Server Technology PRO3X PDUs on firmware 030600.
The 0day Rubbish Research Team publicly disclosed a vulnerability in Server Technology (Legrand) PRO3X intelligent rack PDUs. Firmware spdu-pro3x-030600 build 46640 lets an authenticated attacker override the port_mux listener and run commands as root (CWE-78, CWE-269). A separate hard-coded factory credential is also reported (CWE-798). The post cites no CVE and does not say the flaw is being exploited.