<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Zhonglun - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/zhonglun/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 25 Sep 2026 18:54:46 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/zhonglun/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Injection Vulnerability in Zhonglun CloudPos</title><link>https://feed.craftedsignal.io/briefs/2026-09-zhonglun-cloudpos-rce/</link><pubDate>Fri, 25 Sep 2026 18:54:46 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-zhonglun-cloudpos-rce/</guid><description>A code injection vulnerability in the JSBridge component of Zhonglun CloudPos (up to 3.0.1.76) allows remote attackers to execute arbitrary code via the OpenLocalBrowser function.</description><content:encoded><![CDATA[<p>Zhonglun CloudPos versions up to 3.0.1.76 are vulnerable to a remote code injection flaw located within the JSBridge component. Specifically, the vulnerability exists in the OpenLocalBrowser function found in the file ZlPos/ZlPos/Bizlogic/JSBridge.cs. Attackers can manipulate the url argument processed by this function to achieve remote code execution on affected systems. The vulnerability was publicly disclosed, and there is no evidence that the vendor has addressed the issue or provided a security update. Given the remote exploitability and the lack of vendor response, organizations utilizing this software are at significant risk of unauthorized access and system compromise.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for unauthenticated remote code execution, which could lead to full system compromise, data exfiltration, or the deployment of additional malicious payloads on POS systems. There are no available patches, and the vendor has remained unresponsive to the vulnerability disclosure.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Inventory all instances of Zhonglun CloudPos within the environment and evaluate exposure to internet-facing networks.</li>
<li>Restrict network access to CloudPos instances to known, trusted management segments until a security patch is provided by the vendor.</li>
<li>Monitor endpoint logs for suspicious process spawning from the CloudPos application process, particularly any attempts to launch browsers or shell commands originating from JSBridge-related functions.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>code-injection</category><category>vulnerability</category><category>cve-2026-97871</category></item></channel></rss>