Tag
#SIP
Critical Stack Buffer Overflow Vulnerability in sngrep: CVE-2026-90558
A critical stack buffer overflow vulnerability (CVE-2026-90558) has been discovered in sngrep, a SIP network traffic grep tool, versions up to 1.8.4. The vulnerability has a CVSS score of 9.8 and allows attackers to execute arbitrary code or cause crashes by crafting malicious SIP packets with oversized header fields. The vulnerability is not actively exploited but poses a significant risk due to its high severity and potential for remote exploitation. Organizations are advised to upgrade to a patched version immediately.
Critical Command Injection Vulnerability in Sustainable Irrigation Platform (SIP)
A critical command injection vulnerability (CVE-2026-58479) has been discovered in the Sustainable Irrigation Platform (SIP) through version 5.2.16. The vulnerability, located in the optional cli_control plugin, allows unauthenticated or cross-site request forgery attackers to execute arbitrary operating-system commands. This can be achieved by storing a malicious payload via the plugin's HTTP endpoint and triggering execution by activating the associated irrigation station, exploiting the absence of passphrase protection or the default passphrase 'opendoor'. The vulnerability has a CVSS score of 9.8 and is considered critical.