Remote Code Execution in ProTNS ActADUR
No sign of exploitation. No public exploitation artifact known so far.
ProTNS ActADUR server has critical flaws that allow attackers to run malicious code remotely on affected systems. The vulnerabilities stem from improper input validation, hard-coded passwords, weak authentication, and unrestricted network binding.
Multiple vulnerabilities in ActADUR v2.0.1.9 and earlier enable remote code execution: command injection via unvalidated input parameters, hard-coded credentials allowing unauthorized access, improper authentication mechanisms, and binding to unrestricted IP addresses (0.0.0.0). An unauthenticated or low-privileged attacker can exploit these to achieve arbitrary code execution on the host system. Remediation requires upgrading to v2.0.2.0 or later.