<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: threataft</title>
    <description>The latest articles on DEV Community by threataft (@threataft_dev).</description>
    <link>https://dev.to/threataft_dev</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4149686%2F154f0204-98e0-4763-9356-92e37eb31c9e.png</url>
      <title>DEV Community: threataft</title>
      <link>https://dev.to/threataft_dev</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/threataft_dev"/>
    <language>en</language>
    <item>
      <title>CTranslate2 CVE-2026-102566 &amp; CVE-2026-102567 — Heap Overflow in AI Model Loader</title>
      <dc:creator>threataft</dc:creator>
      <pubDate>Wed, 30 Sep 2026 01:31:21 +0000</pubDate>
      <link>https://dev.to/threataft_dev/ctranslate2-cve-2026-102566-cve-2026-102567-heap-overflow-in-ai-model-loader-552n</link>
      <guid>https://dev.to/threataft_dev/ctranslate2-cve-2026-102566-cve-2026-102567-heap-overflow-in-ai-model-loader-552n</guid>
      <description>&lt;p&gt;A malicious model file is enough to corrupt memory in CTranslate2 — the inference &lt;br&gt;
engine behind Whisper, OpenNMT, and dozens of AI applications.&lt;/p&gt;

&lt;p&gt;Two memory-safety flaws disclosed September 29, 2026. Both affect CTranslate2 before &lt;br&gt;
4.8.1. Both are fixed in 4.8.1.&lt;/p&gt;

&lt;h2&gt;
  
  
  The CVEs
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE&lt;/th&gt;
&lt;th&gt;CVSS&lt;/th&gt;
&lt;th&gt;Type&lt;/th&gt;
&lt;th&gt;Component&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;CVE-2026-102566&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;7.8&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;CWE-120 Heap Buffer Overflow&lt;/td&gt;
&lt;td&gt;Binary model loader&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CVE-2026-102567&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;6.1&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;CWE-125 Out-of-Bounds Read&lt;/td&gt;
&lt;td&gt;String field deserialization&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  What happened
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;CVE-2026-102566&lt;/strong&gt; — The binary model loader reads a payload length from the model &lt;br&gt;
file but never validates it against the allocated heap buffer before copying. Craft a &lt;br&gt;
model file with an inflated length field, write past the heap boundary, corrupt &lt;br&gt;
adjacent memory structures. Arbitrary code execution.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;CVE-2026-102567&lt;/strong&gt; — String fields in model files are deserialized without verifying &lt;br&gt;
a null terminator exists. The loader reads past the buffer into adjacent heap memory — &lt;br&gt;
crash or memory disclosure. In AI-as-a-Service deployments this could expose user data &lt;br&gt;
stored nearby.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why AI pipelines are exposed
&lt;/h2&gt;

&lt;p&gt;CTranslate2 powers Whisper, OpenNMT, and countless custom inference services. Model &lt;br&gt;
files get pulled from Hugging Face, GitHub releases, internal registries — often &lt;br&gt;
automatically in CI/CD pipelines. The attack surface is: anyone who can put a model &lt;br&gt;
file in front of your inference server.&lt;/p&gt;

&lt;p&gt;No public PoC exists yet. The attack requires only that a victim loads the malicious &lt;br&gt;
file.&lt;/p&gt;

&lt;h2&gt;
  
  
  Fix
&lt;/h2&gt;

&lt;p&gt;Upgrade to &lt;strong&gt;CTranslate2 4.8.1&lt;/strong&gt; immediately.&lt;/p&gt;

&lt;p&gt;Until patched:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Restrict model loading to trusted, verified sources&lt;/li&gt;
&lt;li&gt;Validate checksums before loading model files&lt;/li&gt;
&lt;li&gt;Audit any pipeline that ingests third-party models&lt;/li&gt;
&lt;li&gt;Restrict who can upload to model endpoints&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Vulnerabilities reported by Chegne Eu Joe via VulnCheck.&lt;/p&gt;




&lt;p&gt;&lt;em&gt;Full analysis with CVSS vectors, CWE classifications, and mitigation checklist:&lt;/em&gt;&lt;br&gt;&lt;br&gt;
&lt;em&gt;&lt;a href="https://threataft.com/articles/ctranslate2-cve-2026-102566-102567-model-loader" rel="noopener noreferrer"&gt;CTranslate2 CVE-2026-102566 &amp;amp; CVE-2026-102567&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://threataft.com" rel="noopener noreferrer"&gt;ThreatAft&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>security</category>
      <category>cybersecurity</category>
      <category>vulnerabilities</category>
    </item>
    <item>
      <title>RaspAP Mass Disclosure — 3 CVEs, Privilege Escalation + RCE, No Patch</title>
      <dc:creator>threataft</dc:creator>
      <pubDate>Tue, 29 Sep 2026 17:06:00 +0000</pubDate>
      <link>https://dev.to/threataft_dev/raspap-mass-disclosure-3-cves-privilege-escalation-rce-no-patch-16ki</link>
      <guid>https://dev.to/threataft_dev/raspap-mass-disclosure-3-cves-privilege-escalation-rce-no-patch-16ki</guid>
      <description>&lt;p&gt;Three vulnerabilities in RaspAP raspap-webgui were disclosed on September 28, 2026 — all with public proof-of-concept exploits. The vendor was contacted and did not respond. No patches exist.&lt;/p&gt;

&lt;h2&gt;
  
  
  The CVEs
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;CVE&lt;/th&gt;
&lt;th&gt;CVSS&lt;/th&gt;
&lt;th&gt;Type&lt;/th&gt;
&lt;th&gt;Component&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;CVE-2026-101860&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;8.8&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;Privilege escalation&lt;/td&gt;
&lt;td&gt;PluginInstaller::addSudoers&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CVE-2026-101859&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;5.4&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;OS command injection&lt;/td&gt;
&lt;td&gt;OpenVPN del_ovpncfg.php&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;CVE-2026-101858&lt;/td&gt;
&lt;td&gt;&lt;strong&gt;4.7&lt;/strong&gt;&lt;/td&gt;
&lt;td&gt;OS command injection&lt;/td&gt;
&lt;td&gt;WiFiManager::writeWpaSupplicant&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  What happened
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;CVE-2026-101860&lt;/strong&gt; is the serious one. The &lt;code&gt;PluginInstaller::addSudoers&lt;/code&gt; function allows manipulation of the sudoers configuration without adequate authorization checks. An attacker with web interface access can grant themselves unrestricted root execution on the underlying Raspberry Pi OS.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;CVE-2026-101859&lt;/strong&gt; is OS command injection via the &lt;code&gt;cfg_id&lt;/code&gt; parameter in &lt;code&gt;ajax/openvpn/del_ovpncfg.php&lt;/code&gt;. The &lt;code&gt;escapeshellcmd&lt;/code&gt; function is used incorrectly — injection through the OpenVPN configuration deletion handler.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;CVE-2026-101858&lt;/strong&gt; is OS command injection via the &lt;code&gt;ssid&lt;/code&gt; argument in &lt;code&gt;WiFiManager::writeWpaSupplicant&lt;/code&gt;. Requires authenticated access but the barrier is low on a home/edge device.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why it matters
&lt;/h2&gt;

&lt;p&gt;RaspAP is the de facto standard for turning a Raspberry Pi into a wireless router. These devices sit at the network edge. Root compromise via the web UI = foothold inside your local network.&lt;/p&gt;

&lt;p&gt;Public PoCs are available for all three. No vendor fix is coming. The only realistic path is isolation.&lt;/p&gt;

&lt;h2&gt;
  
  
  What to do right now
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Restrict the web interface&lt;/strong&gt; — firewall rules, trusted IPs only&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Monitor /etc/sudoers&lt;/strong&gt; — file integrity monitoring on this path&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Disable plugin installation&lt;/strong&gt; if you don't use it (removes the CVE-2026-101860 attack surface)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Strong authentication&lt;/strong&gt; — change defaults, add 2FA if supported&lt;/li&gt;
&lt;/ol&gt;




&lt;p&gt;&lt;em&gt;Full technical analysis with CVSS vectors, CWE classifications, and mitigation checklist:&lt;/em&gt;&lt;br&gt;
&lt;em&gt;&lt;a href="https://threataft.com/articles/raspap-mass-disclosure-cve-2026-101860-101859-101858" rel="noopener noreferrer"&gt;RaspAP Mass Disclosure — CVE-2026-101860, CVE-2026-101859, CVE-2026-101858&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Originally published at &lt;a href="https://threataft.com" rel="noopener noreferrer"&gt;ThreatAft&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

</description>
      <category>security</category>
      <category>vulnerabilities</category>
      <category>cybersecurity</category>
      <category>networking</category>
    </item>
  </channel>
</rss>
