VU#748485: Unauthenticated configuration modification vulnerability in Central Office Services - Content Hosting Component
2026-05-07T08:52:22Z•fb39e7bb0abc9df70160949b7da69818a9a2383220a61d7a85e34f435cbb5388
DICOMDRC-INSIGHTGGUFMuPDFOllamaOrthancRCERadware-AlteonSGLangTerrariumdata-exfiltrationheap-buffer-overflowheap-memory-leakhttps-proxy-manipulationinformation-disclosureinteger-overflowjinja2-sstimodel-file-sstipatch-availablequantizationreflected-xsssandbox-escapetraffic-redirectionunauthenticated-configuration-modificationzip-gzip-decompression-bomb
What happened
CERT/CC vulnerability notes aggregate multiple high-impact vulnerabilities across diverse products. Notable issues include an unauthenticated configuration-modification endpoint in DRC INSIGHT Central Office Services that allows on‑network attackers to overwrite configuration (including storage credentials and httpsProxy) enabling data exfiltration or traffic interception (CVE-2026-5756); an unauthenticated out‑of‑bounds heap read in Ollama’s GGUF quantization that can leak server heap contents via uploaded models (CVE-2026-5757); a reflected XSS in Radware Alteon allowing JavaScript execution
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- fb39e7bb0abc9df70160949b7da69818a9a2383220a61d7a85e34f435cbb5388
- Enrichment time
- 2026-05-07T08:52:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.