ZeroHour
Organization

CERT/CC

3 mentions in 7 days · 11 in 30 days · 11 total · first seen · last

Timeline

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Spy Through Microphone

Skullcandy Dime 3 earbuds on firmware 1.0.0.28 accept unauthenticated Bluetooth pairing via Airoha SDK flaw CVE-2025-20701, enabling audio hijack and microphone capture.

CERT/CC vulnerability note VU#859658 describes insecure Bluetooth Classic (BR/EDR) pairing on Skullcandy Dime 3 (model S2DCW) firmware 1.0.0.28, linked to CVE-2025-20701 in the Airoha Bluetooth audio SDK. The NoInputNoOutput I/O capability lets unknown nearby devices pair without pairing mode, PIN, passkey or user interaction, then bond and automatically reconnect. An attacker can hijack the A2DP audio session and access Hands-Free or Headset profiles to capture live microphone audio. Firmware 1.0.0.30 reportedly fixes the flaw, but the earbuds cannot be updated through the Skullcandy app, leaving current users without a consumer-accessible patch path.

VU#687587: AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disks

AOMEI Backupper 8.4.0 driver flaw CVE-2026-12780 lets unprivileged users write physical disks and execute UEFI code, bypassing HVCI and EDR.

CERT/CC issued VU#687587 for CVE-2026-12780, an incorrect permission assignment (CWE-732) in the amwrtdrv.sys kernel driver shipped with AOMEI Backupper 8.4.0. The driver exposes a world-accessible device object without a security descriptor, allowing any unprivileged user to write arbitrary physical disk sectors; with Secure Boot disabled, an attacker can modify the GPT and inject a UEFI payload that executes before the OS loads, bypassing HVCI, EDR, Windows Defender and Hyper-V isolation. On TPM-only BitLocker configurations the attack can capture Volume Master Key material during pre-boot. AOMEI has shipped patches; users who cannot update should uninstall the software or disable the amwrtdrv.sys service, and enabling Secure Boot adds defense in depth.

Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

CERT/CC warns Skullcandy Dime 3 earbuds accept silent Bluetooth pairings via CVE-2025-20701, letting nearby attackers hijack audio and microphone.

CERT/CC reports the Skullcandy Dime 3 (model S2DCW) running firmware 1.0.0.28 is affected by CVE-2025-20701, a high-severity missing-authentication flaw in the Airoha Bluetooth Audio SDK. An attacker in close range can pair without user interaction, then hijack audio playback, access the headset profile, and capture live microphone audio. Skullcandy fixed the issue in firmware 1.0.0.30, but existing units have no consumer-accessible update path via the app. The flaw was discovered by ERNW researchers and affects earbud and headphone products from multiple vendors; Apple patched it for Beats Studio Buds in June.

BleepingComputerupdated · 5d agofirst · 6d agoVulnerability 3 sourcesCVE-2025-20701

VU#718077: UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot

CERT/CC details VU#718077: UEFI Shell embedded in SPI flash lets attackers bypass Secure Boot and execute pre-boot code; patches issued.

CERT/CC's VU#718077, reported by Eclypsium researcher Stas Lyakhov, describes how a UEFI Shell embedded in SPI flash can be abused by attackers who can modify UEFI boot configuration, creating multiple boot entries that bypass controls preventing the Shell from launching under Secure Boot. The Shell's dmem and mm commands allow arbitrary physical memory read/write, letting attackers overwrite Secure Boot values and execute unauthorized pre-boot code that can persist across reboots and OS reinstalls while degrading EDR effectiveness. AMI confirmed its Aptio UEFI BDS module is affected (CVE-2026-33197), and Cisco published an advisory for a variation affecting UCS Servers and UCS-based appliances (CVE-2026-20293). Firmware patches are being rolled out through OEM and IBV BIOS build pipelines.

VU#859658: Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerability

Skullcandy Dime 3 earbuds (CVE-2025-20701) accept Bluetooth pairings without owner consent, letting in-range attackers hijack audio or capture microphone; no firmware update path exists.

CERT/CC's VU#859658 describes CVE-2025-20701 in the Airoha Bluetooth audio SDK, present in Skullcandy Dime 3 (Model S2DCW) firmware 1.0.0.28. A direct Bluetooth Classic pairing request with no PIN or physical confirmation completes via NoInputNoOutput, adding the attacker's device as trusted. Attackers in radio range can hijack the A2DP audio session, access the Hands-Free/Headset profile, and capture live microphone audio. Firmware 1.0.0.30 contains the effective patch, but Skullcandy says the Dime 3 does not support app-based firmware updates, leaving existing units unpatchable.

VU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerability

ONLYOFFICE's ownCloud integration plugin 9.12 has an SSRF flaw (CVE-2026-84282) letting authenticated admins probe internal networks; no patch exists yet.

CERT/CC published VU#943094 for a server-side request forgery in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin version 9.12, tracked as CVE-2026-84282. The /apps/onlyoffice/ajax/settings/address endpoint does not validate the user-supplied document server URL, so an authenticated administrator can make the ownCloud server send arbitrary requests to localhost and internal hosts. Differences in error responses (connection failures vs SSL/TLS errors) let attackers enumerate open and closed TCP ports for internal reconnaissance. The vendor could not be reached, so no official patch is available; CERT recommends disabling the plugin and applying egress filtering until a fix ships.

VU#456290: Hugging Face Transformers library writes remote code to disk prior to consent check

CVE-2026-80047: Hugging Face Transformers 4.49.0 through 5.8.1 writes attacker-controlled Python files to disk before the trust_remote_code consent check.

CERT/CC vulnerability note VU#456290 describes CVE-2026-80047 in the Hugging Face Transformers library, affecting versions 4.49.0 through 5.8.1. The library performs a remote module fetch and writes attacker-controlled Python files to the local disk before evaluating the trust_remote_code consent prompt, without user authorization. This violates the security contract enforced across other dynamic module-loading paths in the library. Transformers is a primary framework for training and inference across NLP, vision, audio, video, and multimodal machine learning systems.

Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code

CERT/CC disclosed unpatched Kaltura mwEmbed flaws CVE-2026-19913 and CVE-2026-19912 allowing unauthenticated file reads and remote code execution.

CERT/CC disclosed two unpatched flaws in Kaltura's mwEmbed HTML5 player library, both rooted in unsafe deserialization in mwEmbedLoader.php and exploitable without authentication. CVE-2026-19913 (reporter-scored 9.1) reflects local file contents back via the ServiceUrl parameter, exposing secrets in local.ini; CVE-2026-19912 (reporter-scored 10.0) achieves PHP code execution by writing attacker-controlled objects into web-accessible directories via the uiconf_id parameter. No patch exists and CERT/CC could not reach Kaltura; affected releases include html5lib v2.45, v2.103 and earlier, with the shared multi-tenant CDN hosts also impacted. No exploitation or KEV listing was reported as of August 25, 2026.

VU#728712: Konami's Metal Gear Online 3 contains a heap-based buffer overflow

CERT/CC details CVE-2026-19874, a heap overflow in Metal Gear Online 3 letting match hosts execute code on lobby members' machines.

VU#728712 describes a heap-based buffer overflow in Konami's Metal Gear Online 3, tracked as CVE-2026-19874, affecting version 1.1.2.8 (Steam AppID 287700). The input-validation flaw lies in processing Steam lobby metadata tied to the player-removal feature, letting a match host trigger remote code execution on lobby members' machines via specially crafted data. The game is an 8v8 competitive shooter using Steam Matchmaking for lobbies.

VU#756733: Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability

CERT/CC warns Calix GS7 XGS GS5239XG routers on firmware EXOS/6.6.47 expose an unauthenticated UPnP WANIPConnection service on the public WAN interface.

CERT/CC issued VU#756733 for a missing authentication vulnerability in the Calix GS7 XGS GS5239XG residential gateway running EXOS/6.6.47. The device's UPnP service, implemented with MiniUPnPd 2.3.7, is exposed on the WAN interface by default and does not require authentication, potentially letting remote attackers alter port mappings through the WANIPConnection service. The flaw affects routing, NAT, and firewall functionality for home networks.

CERT/CC Vulnerability Notes · 25d agoVulnerability

VU#874418: RDK-B WebUI contains multiple vulnerabilities

CERT/CC warns RDK-B WebUI rdkb-2025q4-kirkstone contains multiple flaws enabling network attackers to bypass authentication, cause DoS, or potentially execute code.

VU#874418 describes multiple vulnerabilities in the RDK-B WebUI version rdkb-2025q4-kirkstone, the open-source Reference Design Kit for Broadband used in broadband gateways and networking devices. Issues include memory corruption, improper authentication, race conditions, and insufficient input validation. A network-adjacent attacker could bypass authentication, obtain administrative access, cause denial-of-service, or corrupt underlying processes, with potential arbitrary code execution under certain conditions.

CERT/CC Vulnerability Notes · 27d agoVulnerability

Related CVEs

  • In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent.
    In the Airoha Bluetooth audio SDK, there is a possible way to pair Bluetooth audio device without user consent. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
    PoC
  • Unauthenticated RCE in Kaltura mwEmbed HTML5 Player
    Kaltura's HTML5 player library (mwEmbed/html5lib) contains an unauthenticated remote code execution vulnerability (CVE-2026-19912) caused by unsafe PHP deserialization combined with unsanitized filesystem path construction in mwEmbedLoader.php. A remote attacker controls the ServiceUrl parameter, whose response is passed to unserialize(), and supplies a crafted uiconf_id so that fields of the resulting object are written to an attacker-influenced cache path without path validation, allowing arbitrary files to be written to web-accessible locations and code execution as the webserver user; the related advisory headline also notes the flaws could allow reading files. The flaw is rated CVSS 9.8 (critical), requiring no privileges or user interaction over the network. Any deployment serving an affected html5lib v2.x release, including v2.45, v2.103 and earlier, is affected. There is no known public proof-of-concept, the issue is not in CISA's KEV catalog, and EPSS estimates only a 0.6% probability of exploitation within 30 days (46th percentile), indicating no confirmed exploitation yet.
    · Kaltura mwEmbed HTML5 player (html5lib) v2.45, v2.103 and earlier, and other v2.x releases exposing the vulnerable mwEmbedLoader.php endpointlarge
  • Heap-Based Buffer Overflow in Konami Metal Gear Online 3 Enables Code Execution
    CVE-2026-19874 is a critical heap-based buffer overflow (CWE-122) in the lobby-data handling of Konami's Metal Gear Online 3: the code trusts the "kick_num" field for the count of kicked-player identifiers (supplied as "kicked_id_%i" keys) without validating it against the 16-entry buffer sized for the game's maximum match size. An attacker who can supply crafted lobby data, such as a lobby host or participant, can set "kick_num" above 16, causing the parser to write past the end of the kicked-ID buffer and into adjacent memory containing Steam callback handler structures, overwriting function pointers and callback arguments. This can lead to control-flow hijacking and potentially arbitrary code execution within the game process; the CVSS 9.1 score reflects network reachability with no privileges or user interaction required. Any player running the affected title who joins or hosts lobbies with untrusted peers is exposed (the described code path touches Steam callback structures, indicating the Steam-integrated client); no fixed version information is included in the available data. There is currently no public proof-of-concept, no known in-the-wild exploitation, and the issue is not in CISA's KEV; EPSS estimates a 0.7% probability of exploitation within 30 days (52nd percentile).
    · Konami Metal Gear Online 3niche
  • Privileged local BIOS code execution in AMI Aptio V (incomplete input validation)
    AMI's Aptio V UEFI BIOS firmware contains an input-validation flaw classified as CWE-184 (Incomplete List of Disallowed Inputs), meaning a BIOS code path fails to reject all inputs it is supposed to disallow. Triggering it requires local access to the machine, and the CVSS 4.0 metrics show the attacker must already hold high privileges (typically OS-level administrator), with no user interaction needed but elevated attack prerequisites that must be met. Successful exploitation yields arbitrary code execution in the firmware context with high impact on confidentiality, integrity and availability on the affected system and, per the scoring, potentially on subsequent systems - significant for BIOS because firmware-level compromise can persist across OS reinstalls. Any workstation, server or motherboard shipped with AMI Aptio V firmware by an OEM is in scope. No public proof-of-concept, CISA KEV listing, or known in-the-wild exploitation has been reported (EPSS 0.1%); a separate related AMI firmware issue (VU#718077, Secure Boot bypass via a UEFI Shell embedded in SPI flash) is also documented.
    · AMI (American Megatrends International) Aptio V (AptioV) UEFI BIOS firmwaremass
  • Secure Boot bypass via embedded UEFI Shell in UEFI BIOS firmware (CVE-2026-6485)
    CVE-2026-6485 (CWE-489, active code left in production firmware) describes a UEFI Shell module embedded in the SPI Flash of affected UEFI BIOS images that can be used to bypass Secure Boot. An attacker with local access and high privileges (CVSS AV:L/PR:H) — for example a local administrator or someone with physical access — can run shell commands or execute startup scripts through the embedded shell, launching code that Secure Boot does not verify. The result is a break in the Secure Boot chain of trust, allowing unsigned or attacker-controlled code to run at boot (e.g., to install bootkit- or firmware-level persistence), which is why the CVSS scope is 'changed' (S:C) with high impact to confidentiality, integrity, and availability. Affected systems are those whose UEFI BIOS ships with this embedded UEFI Shell module in SPI Flash; the issue is tracked in CERT/CC VU#718077, but the exact vendor, product list, and version ranges are not specified in the available data. There is no known exploitation at this time: no public proof-of-concept exists, the issue is not in CISA KEV, and EPSS estimates only a 0.1% chance of exploitation in the next 30 days.
    · UEFI BIOS firmware with a UEFI Shell module embedded in SPI Flash
  • Pre-Consent Remote Python File Write in Hugging Face Transformers
    CVE-2026-80047 is a flaw in Hugging Face Transformers (versions 4.49.0 through 5.8.1) in which GenerativePreTrainedModel.load_custom_generate() writes a remote Python file (custom_generate/generate.py) from a model repository to the local ~/.cache/huggingface/modules directory before performing the required trust_remote_code consent check. The unconditional file write in dynamic_module_utils.py occurs even when the user declines the trust prompt, inverting the consent-first model enforced by AutoConfig, AutoModel, and AutoTokenizer. Execution of the code is correctly gated, but the write is persistent, so attacker-controlled code remains on disk and can later be executed via stale-cache collisions during otherwise trusted model loads. Affected users are developers, CI pipelines, and applications running affected Transformers versions that load custom generate implementations from remote repositories. There is currently no public proof-of-concept, no known exploitation (EPSS 0.1%), and the issue is not in CISA KEV; it was assigned by CERT/CC under VU#456290.
    · Hugging Face Transformers >= 4.49.0 and <= 5.8.1niche
  • Unauthenticated Local File Disclosure in Kaltura HTML5 Player (mwEmbed)
    The Kaltura HTML5 player (mwEmbed/html5lib) fails to properly validate the ServiceUrl parameter in mwEmbedLoader.php, which is used as the base URL for a backend request and accepts non-HTTP schemes such as file://. An unauthenticated remote attacker can supply a file:// URL, and when the backend request raises an exception or error, the server deserializes the response and reflects its raw contents back to the client in an error message, disclosing arbitrary files readable by the web server user. An attacker gains read access to internal server files, which may include configuration files or credentials, with confidentiality impact only per the CVSS score. Any deployment exposing the vulnerable mwEmbedLoader.php endpoint is affected, including sites running html5lib v2.45, v2.103 and earlier, and other v2.x releases. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known; EPSS is low at 0.4%, though related reporting indicates additional unpatched mwEmbed flaws, possibly including code execution, may exist.
    · Kaltura html5lib / mwEmbed HTML5 player (mwEmbedLoader.php) v2.103 and earlier (including v2.45) and other v2.x releases exposing the vulnerable mwEmbedLoader.php endpoint; no fixed release identified in available reportlarge
  • Secure Boot Bypass via UEFI Shell in Cisco UCS Servers and UCS-based Appliances
    CVE-2026-20293 is a flaw in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances that lets an attacker bypass UEFI Secure Boot validation and run unauthorized software. It is triggered because memory-write commands remain available in the UEFI Shell even while Secure Boot is enabled: an attacker selects the UEFI Shell boot option at boot time and uses shell commands to modify UEFI memory variables and overwrite Secure Boot-related memory values. A successful exploit manipulates the preboot environment and allows execution of untrusted software that would normally be rejected by Secure Boot. Exploitation requires either physical access (no credentials needed) or valid credentials for an account with the user or admin role on the affected system, so practical exposure is limited to systems where an attacker has local access. No exploitation in the wild, public proof-of-concept, or KEV listing is known, and EPSS puts 30-day exploitation probability at about 0.1%.
    · Cisco UCS Servers (UEFI Shell implementation) · Cisco UCS-based appliances (UEFI Shell implementation)large
  • A vulnerability was determined in AOMEI Backupper up to 8.3.0.
    A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.sys of the component Kernel Driver. Executing a manipulation can lead to improper access controls. The attack needs to be launched locally. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
  • SSRF in ONLYOFFICE ownCloud Integration plugin 9.12
    CVE-2026-84282 is a server-side request forgery (SSRF) in the ONLYOFFICE ownCloud Integration plugin version 9.12, where the /apps/onlyoffice/ajax/settings/address endpoint does not sufficiently validate the user-supplied Document Server URL before the ownCloud server makes outbound connections. To trigger it, an authenticated administrator supplies a manipulated 'document server' parameter, causing the server to send requests to attacker-chosen destinations, including localhost and internal network hosts. An attacker gains internal network reconnaissance and can perform TCP port scanning of the ownCloud host's local network by differentiating server responses. Only ownCloud deployments running this integration plugin are affected, and exploitation requires administrative access, so an attacker would typically need a compromised or untrusted admin account. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS puts 30-day exploitation probability at 0.2% (6th percentile).
    · ONLYOFFICE ownCloud Integration plugin 9.12moderate

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.