{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/ecava/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["IntegraXor IGX (16.0.701.10)"],"_cs_severities":["high"],"_cs_tags":["ics","scada","rce","ot"],"_cs_type":"advisory","_cs_vendors":["Ecava"],"content_html":"\u003cp\u003eEcava IntegraXor IGX version 16.0.701.10 contains a critical remote code execution vulnerability originating from an unauthenticated file upload endpoint. The DX Web HMI server (dxweb.exe) exposes a /FileUpload endpoint that lacks authentication and sanitization, allowing remote attackers to write arbitrary files to the underlying Windows host. By uploading a batch script to a temporary directory and a crafted configuration JSON file into the dxmanager configuration directory, an attacker can manipulate the dxmanager.exe orchestrator. Upon service startup or restart, dxmanager.exe enumerates the configuration directory and executes any defined files via cmd.exe /C, resulting in command execution with the privileges of the BUILTIN\\Administrators account. This vulnerability specifically impacts OT and CII manufacturing environments where IntegraXor is deployed as a SCADA/HMI solution.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker sends an unauthenticated POST request to the /FileUpload endpoint on the target IGX web server (port 8081).\u003c/li\u003e\n\u003cli\u003eAttacker provides the 'copyTo' parameter set to 'C:\\Windows\\Temp' and uploads a malicious batch file (igx_payload.bat) containing attacker-specified commands.\u003c/li\u003e\n\u003cli\u003eAttacker sends a second unauthenticated POST request to the /FileUpload endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker provides a 'copyTo' parameter pointing to the dxmanager configuration directory and uploads a configuration JSON file (igx_poc.json).\u003c/li\u003e\n\u003cli\u003eThe JSON file is crafted with a 'meta.name' field containing the absolute path to the previously uploaded batch file (e.g., 'C:\\Windows\\Temp\\igx_payload.bat').\u003c/li\u003e\n\u003cli\u003eThe dxmanager.exe process is triggered to restart via system reboot, service update, crash recovery, or an unauthenticated MQTT Command.Restart.\u003c/li\u003e\n\u003cli\u003eDuring initialization, dxmanager.exe enumerates the configuration directory, reads the malicious JSON file, and invokes 'cmd.exe /C C:\\Windows\\Temp\\igx_payload.bat'.\u003c/li\u003e\n\u003cli\u003eArbitrary commands execute with BUILTIN\\Administrators privileges, achieving full system compromise.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary code with administrative privileges on the SCADA/HMI server. This poses a severe risk to operational technology environments, potentially enabling full control over industrial processes, manipulation of HMI data, and lateral movement within the industrial network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eRestrict network access to the IntegraXor DX Web HMI server (default port 8081) to authorized management workstations only, effectively isolating it from the public internet.\u003c/li\u003e\n\u003cli\u003eImplement strict firewall controls to block access to the /FileUpload endpoint from untrusted networks.\u003c/li\u003e\n\u003cli\u003eDeploy the Sigma rules below to monitor for suspicious process execution patterns originating from the dxmanager service.\u003c/li\u003e\n\u003cli\u003eHunt for anomalous file creation events in the dxmanager configuration directory and C:\\Windows\\Temp\\ involving .bat or .json files.\u003c/li\u003e\n\u003cli\u003eCoordinate with the vendor, Ecava, to obtain security patches and disable non-essential features, specifically the /FileUpload functionality, until a verified fix is applied.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-01T15:12:49Z","date_published":"2026-10-01T15:12:49Z","id":"https://feed.craftedsignal.io/briefs/2026-10-ecava-integraxor-rce/","summary":"Ecava IntegraXor IGX 16.0.701.10 is vulnerable to unauthenticated remote code execution via an insecure file upload endpoint that enables arbitrary command execution during service startup.","title":"Unauthenticated Remote Code Execution in Ecava IntegraXor IGX","url":"https://feed.craftedsignal.io/briefs/2026-10-ecava-integraxor-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Ecava","version":"https://jsonfeed.org/version/1.1"}