Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107785— Crux Agent silently fails SKA preshared key rotation when SHA-512 peering is negotiated

Quick assessment

Affected
Sirius Computer, Inc. Crux Agent
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

漏洞描述: Crux Agent 1.9.0 至 2.0.3(不含 2.0.3)版本在使用全长的 SKA bilocation 密钥作为 WireGuard 预共享密钥(preshared key)时存在安全问题。当对等会话协商使用 SHA-512 算法时,生成的密钥长度为 64 字节,而 WireGuard 要求预共享密钥长度必须为 32 字节。该代理未对此密钥长度进行有效性验证,而是尝试通过执行 命令来更新活动隧道配置,并将无效的密钥写入 WireGuard 配置文件。由于密钥长度不合法,配置更新失败,导致活动

CVSS 6.3 · Medium

Possible ATT&CK Techniques 1 AI

T1557.002 · ARP Cache Poisoning

Affected Version Matrix 1

VendorProduct Version RangeStatus
Sirius Computer, Inc. Crux Agent 1.9.0< 2.0.3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107785

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Crux Agent silently fails SKA preshared key rotation when SHA-512 peering is negotiated
Source: CVE Program / CVE List V5
Vulnerability Description
Crux Agent from 1.9.0 before 2.0.3 uses the full SKA bilocation key as the WireGuard preshared key. When a peering session negotiates use of SHA-512, the key produced is 64 bytes instead of the 32 bytes WireGuard requires. The agent does not validate this size; instead it attempts to use the `wg set` command to update the live tunnel, and write the invalid key to the WireGuard configuration file. The update fails, so the live tunnel keeps using its previous preshared key until the tunnel is shut down. The tunnel will fail to start when restarted. For a peer which has never successfully negotiated a 32-byte bilocation key in a Crux C2 organization which has the "Enforce SKA Use" setting turned off, no preshared key will be set for the tunnel. Therefore, an attacker who is able to intercept and store the peer's traffic, and has access (or will have access) to a cryptographically relevant quantum computer, will be able to decrypt the tunnel.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:U/S:N/AU:Y/R:A/V:C/RE:L/U:Amber
Source: CVE Program / CVE List V5
Vulnerability Type
未预期的状态编码或返回值
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Sirius Computer, Inc. Crux Agent 1.9.0 ~ 2.0.3 -

II. Public POCs for CVE-2026-107785

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107785

请登录查看更多情报信息。

Other References for CVE-2026-107785 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-107785

No comments yet


Leave a comment