Full Disclosure mailing list archives
Security advisory: Pre-authentication RCE (SQL injection) in XPressEntry 3.7.7454 (Telaeris Inc)
From: disclosure via Fulldisclosure <fulldisclosure () seclists org>
Date: Tue, 18 Aug 2026 06:06:02 +0000
0day Rubbish Research Team is publicly disclosing a vulnerability in XPressEntry 3.7.7454 (Telaeris Inc). The research is published and a proof-of-concept is available. Pre-authentication RCE (SQL injection) (CVSS 9.8, pre-authentication) Telaeris XPressEntry 3.7.7454 runs its main HTTP API without authentication when RequireReaderCredentials is False, which is the default. The SaveVerifyActivity handler concatenates the sNotes parameter into an INSERT statement with no escaping. On a SQL Server backend with a sysadmin application account, an unauthenticated attacker uses a COMMIT-breakout payload to enable xp_cmdshell and execute arbitrary commands as LocalSystem. Dynamically verified. Impact: Full compromise of the physical access-control and emergency-mustering system as LocalSystem. The attacker can alter badge records, forge or block entry events, and take over facility-security infrastructure. Advisory: https://0day-rubbish.com/blog/telaeris-xpressentry-unauth-sqli-xpcmdshell-rce PoC and full analysis: https://github.com/Exploit-Garbage/0day-Rubbish Vendor has been notified. CVE ID is pending. -- 0day Rubbish Research Team https://0day-rubbish.com _______________________________________________ Sent through the Full Disclosure mailing list https://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: https://seclists.org/fulldisclosure/
Current thread:
- Security advisory: Pre-authentication RCE (SQL injection) in XPressEntry 3.7.7454 (Telaeris Inc) disclosure via Fulldisclosure (Aug 17)
