{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/visual-integrated-command-and-dispatch-platform/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-18969"},{"cvss":7.3,"id":"CVE-2026-18970"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Visual Integrated Command and Dispatch Platform","Visual Integrated Command and Dispatch Platform (\u003c= 20260617)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Rongzhitong"],"content_html":"\u003cp\u003eCVE-2026-18969 is a high-severity security vulnerability affecting the Rongzhitong Visual Integrated Command and Dispatch Platform versions up to 20260617. The flaw resides in the handling of the 'File' argument within the \u003ccode\u003e/dm/dispatch/userinfo/upload\u003c/code\u003e function. Due to improper access control and insufficient validation of uploaded files, an unauthenticated remote attacker can upload arbitrary files to the server. This vulnerability allows for the potential execution of malicious code, leading to system compromise. Publicly available exploit material for this vulnerability is documented, and the vendor has not provided a response or a patch as of the time of disclosure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated remote attackers to gain unauthorized access to the affected command and dispatch platform. By uploading malicious files (such as web shells), attackers can achieve remote code execution, potentially resulting in full system takeover, exfiltration of sensitive command data, and disruption of critical dispatch services. Given the nature of command and dispatch systems, the potential for operational impact is significant.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection engineering teams should focus on identifying unauthorized attempts to interact with the identified upload endpoint.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided Sigma rule to monitor for suspicious POST requests to the vulnerable upload URI.\u003c/li\u003e\n\u003cli\u003eInspect web server access logs for requests to \u003ccode\u003e/dm/dispatch/userinfo/upload\u003c/code\u003e that do not originate from authorized administrative workflows or that exhibit unusual user-agent strings.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the management and dispatch platform interfaces to only trusted IP ranges via internal firewalls or VPNs to mitigate remote exploitation risks.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T01:21:21Z","date_published":"2026-08-06T01:21:18Z","id":"https://feed.craftedsignal.io/briefs/2026-08-rongzhitong-upload/","summary":"An unauthenticated remote code execution vulnerability (CVE-2026-18969) exists in the Rongzhitong Visual Integrated Command and Dispatch Platform due to an unrestricted file upload flaw in the /dm/dispatch/userinfo/upload endpoint.","title":"Unrestricted File Upload Vulnerability in Rongzhitong Visual Integrated Command and Dispatch Platform","url":"https://feed.craftedsignal.io/briefs/2026-08-rongzhitong-upload/"}],"language":"en","title":"CraftedSignal Threat Feed - Visual Integrated Command and Dispatch Platform","version":"https://jsonfeed.org/version/1.1"}