Pi.Alert是jokob-sk个人开发者的一款 WIFI / LAN 入侵检测器。 Pi.Alert 2026-05-07之前版本存在代码注入漏洞,该漏洞源于Web配置编辑器允许注入任意Python代码到pialert.conf文件,且后台扫描守护进程通过Python的exec()加载该文件,可能导致未认证的远程代码执行攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-44888 | 9.8 CRITICAL | Unauthenticated RCE via Python Config File Injection in SaveConfigFile() (Interger) |
| CVE-2026-44886 | Pi.Alert: Web Interface Vulnerable to Unauthenticated Blind SQL Injection |
No comments yet