<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>IntegraXor IGX (16.0.701.10) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/integraxor-igx-16.0.701.10/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 15:12:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/integraxor-igx-16.0.701.10/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Remote Code Execution in Ecava IntegraXor IGX</title><link>https://feed.craftedsignal.io/briefs/2026-10-ecava-integraxor-rce/</link><pubDate>Thu, 01 Oct 2026 15:12:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-ecava-integraxor-rce/</guid><description>Ecava IntegraXor IGX 16.0.701.10 is vulnerable to unauthenticated remote code execution via an insecure file upload endpoint that enables arbitrary command execution during service startup.</description><content:encoded><![CDATA[<p>Ecava IntegraXor IGX version 16.0.701.10 contains a critical remote code execution vulnerability originating from an unauthenticated file upload endpoint. The DX Web HMI server (dxweb.exe) exposes a /FileUpload endpoint that lacks authentication and sanitization, allowing remote attackers to write arbitrary files to the underlying Windows host. By uploading a batch script to a temporary directory and a crafted configuration JSON file into the dxmanager configuration directory, an attacker can manipulate the dxmanager.exe orchestrator. Upon service startup or restart, dxmanager.exe enumerates the configuration directory and executes any defined files via cmd.exe /C, resulting in command execution with the privileges of the BUILTIN\Administrators account. This vulnerability specifically impacts OT and CII manufacturing environments where IntegraXor is deployed as a SCADA/HMI solution.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker sends an unauthenticated POST request to the /FileUpload endpoint on the target IGX web server (port 8081).</li>
<li>Attacker provides the 'copyTo' parameter set to 'C:\Windows\Temp' and uploads a malicious batch file (igx_payload.bat) containing attacker-specified commands.</li>
<li>Attacker sends a second unauthenticated POST request to the /FileUpload endpoint.</li>
<li>Attacker provides a 'copyTo' parameter pointing to the dxmanager configuration directory and uploads a configuration JSON file (igx_poc.json).</li>
<li>The JSON file is crafted with a 'meta.name' field containing the absolute path to the previously uploaded batch file (e.g., 'C:\Windows\Temp\igx_payload.bat').</li>
<li>The dxmanager.exe process is triggered to restart via system reboot, service update, crash recovery, or an unauthenticated MQTT Command.Restart.</li>
<li>During initialization, dxmanager.exe enumerates the configuration directory, reads the malicious JSON file, and invokes 'cmd.exe /C C:\Windows\Temp\igx_payload.bat'.</li>
<li>Arbitrary commands execute with BUILTIN\Administrators privileges, achieving full system compromise.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary code with administrative privileges on the SCADA/HMI server. This poses a severe risk to operational technology environments, potentially enabling full control over industrial processes, manipulation of HMI data, and lateral movement within the industrial network.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Restrict network access to the IntegraXor DX Web HMI server (default port 8081) to authorized management workstations only, effectively isolating it from the public internet.</li>
<li>Implement strict firewall controls to block access to the /FileUpload endpoint from untrusted networks.</li>
<li>Deploy the Sigma rules below to monitor for suspicious process execution patterns originating from the dxmanager service.</li>
<li>Hunt for anomalous file creation events in the dxmanager configuration directory and C:\Windows\Temp\ involving .bat or .json files.</li>
<li>Coordinate with the vendor, Ecava, to obtain security patches and disable non-essential features, specifically the /FileUpload functionality, until a verified fix is applied.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>ics</category><category>scada</category><category>rce</category><category>ot</category></item></channel></rss>