{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-97871/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zhonglun:cloudpos:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-97871"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["CloudPos (\u003c= 3.0.1.76)"],"_cs_severities":["high"],"_cs_tags":["code-injection","vulnerability","cve-2026-97871"],"_cs_type":"advisory","_cs_vendors":["Zhonglun"],"content_html":"\u003cp\u003eZhonglun CloudPos versions up to 3.0.1.76 are vulnerable to a remote code injection flaw located within the JSBridge component. Specifically, the vulnerability exists in the OpenLocalBrowser function found in the file ZlPos/ZlPos/Bizlogic/JSBridge.cs. Attackers can manipulate the url argument processed by this function to achieve remote code execution on affected systems. The vulnerability was publicly disclosed, and there is no evidence that the vendor has addressed the issue or provided a security update. Given the remote exploitability and the lack of vendor response, organizations utilizing this software are at significant risk of unauthorized access and system compromise.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthenticated remote code execution, which could lead to full system compromise, data exfiltration, or the deployment of additional malicious payloads on POS systems. There are no available patches, and the vendor has remained unresponsive to the vulnerability disclosure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInventory all instances of Zhonglun CloudPos within the environment and evaluate exposure to internet-facing networks.\u003c/li\u003e\n\u003cli\u003eRestrict network access to CloudPos instances to known, trusted management segments until a security patch is provided by the vendor.\u003c/li\u003e\n\u003cli\u003eMonitor endpoint logs for suspicious process spawning from the CloudPos application process, particularly any attempts to launch browsers or shell commands originating from JSBridge-related functions.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-25T18:54:46Z","date_published":"2026-09-25T18:54:46Z","id":"https://feed.craftedsignal.io/briefs/2026-09-zhonglun-cloudpos-rce/","summary":"A code injection vulnerability in the JSBridge component of Zhonglun CloudPos (up to 3.0.1.76) allows remote attackers to execute arbitrary code via the OpenLocalBrowser function.","title":"Remote Code Injection Vulnerability in Zhonglun CloudPos","url":"https://feed.craftedsignal.io/briefs/2026-09-zhonglun-cloudpos-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-97871","version":"https://jsonfeed.org/version/1.1"}