Tag
high
advisory
CVE-2026-64619: FileCodeBox Rate Limit Bypass Vulnerability
2 TTPs 1 CVE 4 IOCsUnauthenticated attackers can bypass rate limits in FileCodeBox versions before 2.4 due to a vulnerability in the IPRateLimit class, allowing them to enumerate share codes and retrieve other users' files without authentication by spoofing X-Real-IP and X-Forwarded-For headers without proper verification.
FileCodeBox
rate-limit-bypass
vulnerability
web-application
file-sharing
data-exfiltration
cve
2t
1c
4i
high
advisory
9router: Login Brute-Force Protection Bypass via Spoofed X-Forwarded-For Header
1 rule 2 TTPsThe 9router dashboard login rate limiter incorrectly uses the attacker-controlled X-Forwarded-For HTTP header to identify clients, leading to a brute-force protection bypass (CVE-2026-55501) that allows attackers to circumvent the lockout mechanism and conduct unlimited password brute-force attempts to gain administrative access.
9router
brute-force
rate-limit-bypass
x-forwarded-for
vulnerability
web-application
1r
2t