<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Synetics GmbH - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/synetics-gmbh/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sat, 10 Oct 2026 06:53:40 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/synetics-gmbh/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated Remote Code Execution in i-doit Pro via Weak Admin Credentials</title><link>https://feed.craftedsignal.io/briefs/2026-10-idoit-rce/</link><pubDate>Sat, 10 Oct 2026 06:53:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-idoit-rce/</guid><description>A vulnerability in i-doit Pro (versions 25 and below) allows attackers to perform brute-force attacks on the admin-center, enabling the upload of malicious plugins to achieve remote code execution.</description><content:encoded><![CDATA[<p>i-doit Pro versions 25 and below contain a critical vulnerability (CVE-2023-37756) stemming from weak password complexity requirements in the admin-center interface. By default, or through administrative misconfiguration, the system allows for trivial passwords, enabling attackers to perform brute-force attacks against the 'admin' account. Once unauthorized access to the admin-center is obtained, an attacker can leverage the plugin management functionality to upload a backdoored archive. By modifying the 'init.php' file within a legitimate plugin archive to include arbitrary system commands, an attacker can achieve remote code execution (RCE) with the privileges of the web server process. The payload executes when an administrator or user activates the compromised plugin, posing a significant risk to the integrity and confidentiality of the CMDB data managed by i-doit Pro.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An attacker identifies an internet-facing i-doit Pro admin-center interface.</li>
<li>The attacker initiates a brute-force or credential-guessing attack against the default 'admin' account due to lack of enforced password complexity.</li>
<li>Upon successful authentication, the attacker navigates to the 'Add-on' section within the admin-center.</li>
<li>The attacker uploads a legitimate plugin archive and extracts the contents locally.</li>
<li>The attacker modifies the 'init.php' file within the plugin to include a reverse shell or other arbitrary command execution payload, ensuring the process is backgrounded to prevent application crashes.</li>
<li>The attacker re-archives the modified plugin folder as a ZIP file.</li>
<li>The attacker uploads the malicious plugin via the 'Upload' function in the admin-center.</li>
<li>The attacker activates the plugin; the payload executes when the system processes the 'init.php' file, resulting in remote code execution.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to gain full administrative control over the i-doit Pro environment. This results in potential unauthorized access to sensitive IT infrastructure documentation, full system compromise, and the ability to execute arbitrary code on the underlying web server, likely leading to data exfiltration or lateral movement within the network.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Immediately restrict access to the i-doit Pro admin-center to trusted management networks using firewall rules.</li>
<li>Enforce strong password complexity policies for all administrative accounts, specifically targeting the 'admin' account, as the default configuration may permit trivial passwords.</li>
<li>Audit existing plugins for unauthorized modifications by verifying the file integrity of 'init.php' and other executable components against known-good baselines.</li>
<li>Monitor web server logs for suspicious POST requests to the plugin upload endpoint and repeated failed login attempts to the admin-center.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>remote-code-execution</category><category>brute-force</category><category>web-application-vulnerability</category></item></channel></rss>