{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/genieacs-mcp--0.3.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-55637"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["genieacs-mcp (\u003c= 0.3.1)"],"_cs_severities":["high"],"_cs_tags":["dns-rebinding","mcp","genieacs","remote-code-execution"],"_cs_type":"advisory","_cs_vendors":["GeiserX"],"content_html":"\u003cp\u003eThe \u003ccode\u003egenieacs-mcp\u003c/code\u003e package (versions \u0026lt;= 0.3.1) is vulnerable to a DNS rebinding attack that exploits an unauthenticated Streamable HTTP MCP endpoint. By default, the package binds to \u003ccode\u003e127.0.0.1:8080\u003c/code\u003e and does not enforce authentication, relying on the loopback address as a security boundary. However, browsers can be coerced into sending requests to this loopback address via DNS rebinding from a malicious web page. Because the MCP server fails to validate \u003ccode\u003eHost\u003c/code\u003e and \u003ccode\u003eOrigin\u003c/code\u003e headers, it accepts these requests, allowing the attacker to initialize an MCP session and execute sensitive device management tools. This vulnerability effectively permits remote control over the underlying GenieACS NBI interface, enabling actions such as device reboots, firmware updates, and modification of TR-069 configuration parameters.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe victim visits an attacker-controlled website which initiates a DNS rebinding sequence against an internal or localhost domain.\u003c/li\u003e\n\u003cli\u003eThe browser is directed to resolve a malicious domain to \u003ccode\u003e127.0.0.1\u003c/code\u003e, bypassing the Same-Origin Policy.\u003c/li\u003e\n\u003cli\u003eThe malicious website sends a crafted HTTP POST request to the local \u003ccode\u003egenieacs-mcp\u003c/code\u003e listener at \u003ccode\u003e127.0.0.1:8080/mcp\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003egenieacs-mcp\u003c/code\u003e server processes the request without verifying the \u003ccode\u003eHost\u003c/code\u003e or \u003ccode\u003eOrigin\u003c/code\u003e headers, assuming the loopback traffic is benign.\u003c/li\u003e\n\u003cli\u003eThe attacker initializes an MCP session by sending a JSON-RPC \u003ccode\u003einitialize\u003c/code\u003e request, receiving a session ID.\u003c/li\u003e\n\u003cli\u003eThe attacker invokes administrative tools such as \u003ccode\u003eget_parameter\u003c/code\u003e or \u003ccode\u003ereboot_device\u003c/code\u003e via \u003ccode\u003etools/call\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003egenieacs-mcp\u003c/code\u003e backend relays these authenticated tool calls to the target GenieACS NBI, leading to unauthorized device management actions.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a remote attacker to act as an authenticated user of the GenieACS MCP interface. This results in unauthorized control over device fleets, including the ability to reboot CPE devices, initiate firmware downloads, and modify TR-069 device parameters. Exposure of these management interfaces presents a significant risk to the integrity and availability of the managed network devices.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade \u003ccode\u003egenieacs-mcp\u003c/code\u003e to a version that enforces strict \u003ccode\u003eHost\u003c/code\u003e and \u003ccode\u003eOrigin\u003c/code\u003e header validation for all HTTP transport requests, including loopback.\u003c/li\u003e\n\u003cli\u003eFor current deployments, implement a reverse proxy or WAF layer that rejects requests to the MCP endpoint if the \u003ccode\u003eHost\u003c/code\u003e and \u003ccode\u003eOrigin\u003c/code\u003e headers do not match expected local values (e.g., \u003ccode\u003e127.0.0.1:8080\u003c/code\u003e or \u003ccode\u003elocalhost:8080\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eRequire a bearer token for all HTTP transport configurations, even for local loopback interfaces, to mitigate the risk of unauthenticated requests.\u003c/li\u003e\n\u003cli\u003eConsider migrating to the \u003ccode\u003estdio\u003c/code\u003e transport mode if HTTP-based MCP bridging is not strictly required for the specific integration.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-25T18:49:34Z","date_published":"2026-08-25T18:49:34Z","id":"https://feed.craftedsignal.io/briefs/2026-08-genieacs-mcp-dns-rebinding/","summary":"The genieacs-mcp package fails to validate Host and Origin headers on loopback listeners, allowing unauthorized web pages to perform DNS rebinding and invoke administrative GenieACS tools via an unauthenticated MCP interface.","title":"DNS Rebinding Vulnerability in GenieACS MCP Streamable HTTP Transport","url":"https://feed.craftedsignal.io/briefs/2026-08-genieacs-mcp-dns-rebinding/"}],"language":"en","title":"CraftedSignal Threat Feed - Genieacs-Mcp (\u003c= 0.3.1)","version":"https://jsonfeed.org/version/1.1"}