{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/corget/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["GpsDget 2_3.2"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Corget"],"content_html":"\u003cp\u003eCorget GpsDget version 2_3.2 contains an OS command injection vulnerability within its PTTServer HTTP service. The flaw resides in the handling of the 'Target' header during a POST request to the 'SendEmail' method. Analysis of the HttpHandler.cpp source code reveals that user-supplied input from the 'Target' header is insecurely concatenated into a system() call without proper sanitization.\u003c/p\u003e\n\u003cp\u003eThis vulnerability allows unauthenticated remote attackers to inject arbitrary shell commands. Because the service executes these commands with root privileges, exploitation results in full system compromise. The issue was identified in GpsDget version 2_3.2 (build 2020-09-01) of the Gps2.0 product line. Defenders should note that this vulnerability has an active public proof-of-concept exploit available (EDB-52631), which specifically targets the PTTServer component.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify systems running the PTTServer service via public exposure.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP POST request to the target web service.\u003c/li\u003e\n\u003cli\u003eThe request includes the 'Method' header set to 'SendEmail'.\u003c/li\u003e\n\u003cli\u003eThe request includes a malicious payload in the 'Target' header containing shell metacharacters (e.g., x;\u0026lt;cmd\u0026gt;;).\u003c/li\u003e\n\u003cli\u003eThe PTTServer application parses the headers and passes the 'Target' value directly to a system() call.\u003c/li\u003e\n\u003cli\u003eThe underlying operating system executes the injected shell command as the root user.\u003c/li\u003e\n\u003cli\u003eAttacker achieves persistent access, data exfiltration, or further lateral movement from the compromised host.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation grants an unauthenticated attacker full root-level control over the target system. This allows for total compromise of the affected device, including data theft, installation of backdoors, or use of the device in further attacks. As this service is often used in GPS and PTT infrastructure, this vulnerability represents a significant threat to internal operational systems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of all internet-facing instances of Corget GpsDget and restrict access to the PTTServer interface. If patching is unavailable, implement network-level egress filtering and proxy inspection to block HTTP requests containing suspicious shell metacharacters in the 'Target' header. Monitor system logs for unexpected execution of system utilities or shell commands originating from the GpsDget process or user.\u003c/p\u003e\n","date_modified":"2026-08-10T14:37:45Z","date_published":"2026-08-10T14:37:45Z","id":"https://feed.craftedsignal.io/briefs/2026-08-corget-rce/","summary":"Corget GpsDget 2_3.2 is vulnerable to unauthenticated OS command injection via the HTTP SendEmail method, allowing root-level code execution.","title":"OS Command Injection in Corget GpsDget","url":"https://feed.craftedsignal.io/briefs/2026-08-corget-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Corget","version":"https://jsonfeed.org/version/1.1"}