Genian SSL PNS 中存在一个不当的权限管理漏洞,攻击者可通过在 CSV 批量用户注册过程中操纵“权限”字段,将自身权限提升至超级管理员级别,并强制创建操作系统账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Genians, Inc | Genian SSL PNS (frodo-core) | 0 ~ 5.0.0 | - |
|
| Genians, Inc | Genian SSL PNS (watchcat-ui) | 0 ~ 5.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76142 | 9.3 CRITICAL | Genians, Inc. Genian NAC/ZTNA Improper Access Control on the Internal Interface |
| CVE-2026-76146 | 8.4 HIGH | Genians, Inc Genian SSL PNS OS Command Injection |
| CVE-2026-76143 | 7.3 HIGH | Genians, Inc Genian SSL PNS Multi Factor Authentication Bypass |
| CVE-2026-76147 | 5.9 MEDIUM | Genians, Inc Genian NAC/ZTNA Remote Code Execution |
| CVE-2026-76144 | 1.8 LOW | Genians, Inc Genian SSL PNS Unrestricted File Upload |
No comments yet