Posted by disclosure via Fulldisclosure on Sep 26 0day Rubbish Research Team is publicly disclosing a vulnerability in Server Technology (Legrand group) PRO3X series intelligent rack PDUs, firmware spdu-pro3x-030600 build 46640 (ARM 32-bit uClibc Linux). Type: authenticated listener program override leading to root command execution (CWE-78, CWE-269; a separate hard-coded factory credential is reported as CWE-798).

Read the full article at Full Disclosure →