Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-27558 PoC — IEEE P802.11-REVme 安全漏洞

Source
Associated Vulnerability
Title: IEEE P802.11-REVme 安全漏洞 (CVE-2025-27558)
Description:IEEE P802.11-REVme D1.1 through D7.0 allows FragAttacks against mesh networks. In mesh networks using Wi-Fi Protected Access (WPA, WPA2, or WPA3) or Wired Equivalent Privacy (WEP), an adversary can exploit this vulnerability to inject arbitrary frames towards devices that support receiving non-SSP A-MSDU frames. NOTE: this issue exists because of an incorrect fix for CVE-2020-24588. P802.11-REVme, as of early 2025, is a planned release of the 802.11 standard.
Description
Patching CVE-2025-27558 vulnerability that had affected my linux image.
Readme
# CVE-2025-27558_Patching
Patching CVE-2025-27558 vulnerability that had affected my linux image.

#  Atlas Incident: Unexpected Outbound Connection (197.155.77.1)

This folder documents a real-world network anomaly detected on the *Atlas* machine, a Wazuh-monitored Ubuntu system.

During a routine system update to patch CVE-2025-27558, Atlas unexpectedly attempted to fetch packages from a misconfigured HTTP mirror at 197.155.77.1:80. The server was publicly exposing directory listings (CPAN/) and returned 404 errors — triggering a full incident investigation.

###  What’s Inside

- incident-atlas-mirror-anomaly.md  
  Full case file: discovery, investigation steps, tools used, root cause analysis, and resolution.

###  Skills Demonstrated

- Threat detection & hunting
- Package manager forensics
- Mirror validation & hardening
- Vulnerability patching (CVE-2025-27558)
- Documentation & SOC reporting

---![Screenshot 2025-06-25 133236](https://github.com/user-attachments/assets/20c09707-643a-4b43-8725-3939215c99cf)


System now patched, secure, and fully monitored. 
Logged as part of Jeffrey’s cybersecurity homelab portfolio.
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →