<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-62253 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-62253/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 16:57:01 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-62253/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Hardcoded Default Administrative Password in Homer</title><link>https://feed.craftedsignal.io/briefs/2026-10-homer-hardcoded-credentials/</link><pubDate>Wed, 07 Oct 2026 16:57:01 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-homer-hardcoded-credentials/</guid><description>Fresh deployments of Homer use a hardcoded default password for the admin account, allowing unauthenticated remote attackers to gain full administrative access via CVE-2026-62252.</description><content:encoded><![CDATA[<p>Homer versions prior to 0.0.0-20260625091610-b2e942031ff8 contain a critical vulnerability (CVE-2026-62252) involving the use of hardcoded credentials. During the bootstrap process of a fresh deployment configured with internal authentication, the application automatically initializes an 'admin' account using a hardcoded SHA-256 hash that corresponds to the plaintext password 'sipcapture'.</p>
<p>The application lacks a first-login forced-password-change mechanism or any restrictive policy to prevent immediate unauthorized access. An attacker who can reach the login endpoint of a freshly deployed instance can perform a simple authentication request to obtain an administrative JSON Web Token (JWT). This vulnerability (CWE-798) grants the attacker full administrative control over the capture server, enabling them to manipulate packet capture settings, access sensitive session data, or further compromise the underlying host.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs network reconnaissance to identify reachable Homer instances over the network.</li>
<li>Attacker probes the endpoint '/api/v3/auth' to confirm the Homer instance is using internal authentication.</li>
<li>Attacker sends a POST request to '/api/v3/auth' with the username 'admin' and password 'sipcapture'.</li>
<li>The application validates the password against the hardcoded <code>DefaultInternalAuthPasswordHash</code> and returns an administrative JWT.</li>
<li>Attacker utilizes the returned token in the 'Authorization' header of subsequent requests.</li>
<li>Attacker calls '/api/v3/users' or other administrative APIs to manage users or access stored packet capture data.</li>
<li>Attacker maintains administrative persistence by modifying system configurations or creating new administrative accounts.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full administrative compromise of the Homer application. Attackers can view sensitive metadata and session traffic, export captured data, or modify system configurations. Any organization running a fresh instance of Homer that has not been patched or manually secured is at risk of immediate takeover.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Immediately upgrade all Homer deployments to version 0.0.0-20260625091610-b2e942031ff8 or later to remediate CVE-2026-62252.</li>
<li>Scan perimeter-facing web infrastructure for HTTP traffic directed at /api/v3/auth, focusing on requests using the default 'admin' username.</li>
<li>Deploy the webserver-category Sigma rule below to detect and block unauthorized authentication attempts.</li>
<li>Audit existing Homer installations for administrative users created shortly after deployment to ensure password rotation has been enforced.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>cve-2026-62252</category><category>authentication</category><category>web-application</category><category>authentication-bypass</category><category>cve-2026-62253</category><category>sipcapture</category><category>sqli</category><category>vulnerability</category></item></channel></rss>