MikroTik RouterOS 7.19.1 – Reflected XSS

# Exploit Title: MikroTik RouterOS 7.19.1 – Reflected XSS # Google Dork: inurl:/login?dst= # Date: 2025-07-15 # Exploit Author: Prak Sokchea # Vendor Homepage: https://mikrotik.com # Software Link: https://mikrotik.com/download # Version: RouterOS <= 7.19.1 # Tested on: MikroTik CHR 7.19.1 # CVE : CVE-2025-6563 # PoC: # Visit the following URL while connected to…

Read More

SugarCRM 14.0.0 – SSRF/Code Injection

# Exploit Title : SugarCRM 14.0.0 – SSRF/Code Injection # Author: Egidio Romano aka EgiX # Email : n0b0d13s@gmail.com # Software Link: https://www.sugarcrm.com # Affected Versions: All commercial versions before 13.0.4 and 14.0.1. # CVE Reference: CVE-2024-58258 # Vulnerability Description: User input passed through GET parameters to the /css/preview REST API endpoint is…

Read More

TOTOLINK N300RB 8.54 – Command Execution

# Title: TOTOLINK N300RB 8.54 – Command Execution # Author: Skander BELABED – Magellan Sécurité # Date: 07/11/2025 # Vendor: TOTOLINK # Product: N300RB # Firmware version: 8.54 # CVE: CVE-2025-52089 ## Description: A hidden remote support feature protected by a static secret in TOTOLINK N300RB firmware version 8.54 allows an authenticated attacker to…

Read More