<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Visual Integrated Command and Dispatch Platform - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/visual-integrated-command-and-dispatch-platform/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 06 Aug 2026 01:21:18 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/visual-integrated-command-and-dispatch-platform/feed.xml" rel="self" type="application/rss+xml"/><item><title>Unrestricted File Upload Vulnerability in Rongzhitong Visual Integrated Command and Dispatch Platform</title><link>https://feed.craftedsignal.io/briefs/2026-08-rongzhitong-upload/</link><pubDate>Thu, 06 Aug 2026 01:21:18 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-rongzhitong-upload/</guid><description>An unauthenticated remote code execution vulnerability (CVE-2026-18969) exists in the Rongzhitong Visual Integrated Command and Dispatch Platform due to an unrestricted file upload flaw in the /dm/dispatch/userinfo/upload endpoint.</description><content:encoded><![CDATA[<p>CVE-2026-18969 is a high-severity security vulnerability affecting the Rongzhitong Visual Integrated Command and Dispatch Platform versions up to 20260617. The flaw resides in the handling of the 'File' argument within the <code>/dm/dispatch/userinfo/upload</code> function. Due to improper access control and insufficient validation of uploaded files, an unauthenticated remote attacker can upload arbitrary files to the server. This vulnerability allows for the potential execution of malicious code, leading to system compromise. Publicly available exploit material for this vulnerability is documented, and the vendor has not provided a response or a patch as of the time of disclosure.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthenticated remote attackers to gain unauthorized access to the affected command and dispatch platform. By uploading malicious files (such as web shells), attackers can achieve remote code execution, potentially resulting in full system takeover, exfiltration of sensitive command data, and disruption of critical dispatch services. Given the nature of command and dispatch systems, the potential for operational impact is significant.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Detection engineering teams should focus on identifying unauthorized attempts to interact with the identified upload endpoint.</p>
<ul>
<li>Deploy the provided Sigma rule to monitor for suspicious POST requests to the vulnerable upload URI.</li>
<li>Inspect web server access logs for requests to <code>/dm/dispatch/userinfo/upload</code> that do not originate from authorized administrative workflows or that exhibit unusual user-agent strings.</li>
<li>Restrict network access to the management and dispatch platform interfaces to only trusted IP ranges via internal firewalls or VPNs to mitigate remote exploitation risks.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category></item></channel></rss>