TOTOLINK N300RB 8.54 – Command Execution

# Title: TOTOLINK N300RB 8.54 – Command Execution # Author: Skander BELABED – Magellan Sécurité # Date: 07/11/2025 # Vendor: TOTOLINK # Product: N300RB # Firmware version: 8.54 # CVE: CVE-2025-52089 ## Description: A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to…

Read More

Langflow 1.2.x – Remote Code Execution (RCE)

#!/usr/bin/env python3 # Exploit Title: Langflow 1.2.x – Remote Code Execution (RCE) # Date: 2025-07-11 # Exploit Author: Raghad Abdallah Al-syouf # Vendor Homepage: https://github.com/logspace-ai/langflow # Software Link: https://github.com/logspace-ai/langflow/releases # Version: <= 1.2.x # Tested on: Ubuntu / Docker # CVE: CVE-2025-3248 # Description: #Langflow exposes a vulnerable endpoint `/api/v1/validate/code` that improperly evaluates arbitrary…

Read More

Microsoft Graphics Component Windows 11 Pro (Build 26100+) – Local Elevation of Privileges

**Exploit Title : Microsoft Graphics Component Windows 11 Pro (Build 26100+) – Local Elevation of Privileges **Author:** nu11secur1ty **Date:** 07/11/2025 — ## Overview This repository contains a PowerShell script to **validate whether a Windows 11 system is vulnerable to CVE-2025-49744**—a critical local privilege escalation vulnerability involving the `gdi32.dll` and `win32kfull.sys` system components. …

Read More