{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aattached_devices_tab/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:*:attached_devices_tab:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-27552"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["attached_devices_tab"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","web-application","cve-2026-27552"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eCVE-2026-27552 describes an improper authorization vulnerability located in the /index.php/attached_devices_tab/do_upload endpoint. The vulnerability allows an authenticated, low-privileged remote attacker to bypass intended authorization checks to upload IODD files directly to the device. Exploitation of this flaw can result in significant operational impact, including the alteration of device behavior or the triggering of system crashes leading to a denial-of-service condition. This vulnerability is particularly critical for network infrastructure security as it allows for the unauthorized modification of device configurations or operational logic. Defenders should focus on monitoring for unauthorized file uploads to the identified endpoint and restricting access to administrative functions to authenticated users with documented legitimate requirements for these actions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-27552 enables attackers to manipulate device behavior, potentially leading to full control over affected device logic or creating persistent denial-of-service conditions by crashing the device service. Given the nature of the endpoint, this vulnerability could be weaponized to target critical network infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImplement strict access control lists (ACLs) to restrict access to the /index.php/attached_devices_tab/do_upload endpoint to only authorized administrative network segments.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for any unauthorized POST requests targeting the /index.php/attached_devices_tab/do_upload URI.\u003c/li\u003e\n\u003cli\u003eVerify vendor-specific security patches or configuration guidance to remediate the authorization flaw in the target device firmware.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-16T09:48:57Z","date_published":"2026-09-16T09:48:57Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-27552/","summary":"An improper authorization vulnerability in the /index.php/attached_devices_tab/do_upload endpoint allows low-privileged remote attackers to upload arbitrary files, potentially leading to unauthorized device behavior or denial-of-service.","title":"Improper Authorization in Device Upload Endpoint (CVE-2026-27552)","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-27552/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:*:attached_devices_tab:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}