Vendor
high
advisory
Remote Server-Side Request Forgery in Sipeed PicoClaw (CVE-2026-16084)
1 rule 3 TTPs 1 CVE 9 IOCsA server-side request forgery (SSRF) vulnerability, CVE-2026-16084, has been identified in Sipeed PicoClaw versions up to 0.2.9, allowing remote exploitation due to a weakness in the `web_fetch` function of `pkg/tools/integration/web.go`, with a public exploit available.
PicoClaw
ssrf
vulnerability
remote-exploitation
sipeed
1r
3t
1c
9i
high
advisory
CVE-2026-15319: Remote Improper Access Control in Sipeed PicoClaw
1 CVEA remote improper access control vulnerability (CVE-2026-15319) exists in the IPAllowlist function of the Launcher component in Sipeed PicoClaw versions up to and including 0.2.9, allowing unauthorized remote access due to publicly disclosed exploit.
PicoClaw <= 0.2.9
vulnerability
access-control
web-application
1c
high
advisory
PicoClaw Web Launcher Management Plane Command Injection Vulnerability
2 rules 1 TTP 1 CVEPicoClaw version 0.2.4 is vulnerable to command injection via the /api/gateway/restart endpoint of the Web Launcher Management Plane, allowing a remote attacker to execute arbitrary commands by manipulating input.
PicoClaw
command-injection
vulnerability
web-application
2r
1t
1c