CVE-2025-22871
CVSS 9.1 CRITICAL: the net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. EPSS 0.8% (55º percentile).
Vulnerabilità ed exploit · Attacco ad app web
Una falla nel confine delle web request nel SENTRON 7KT PAC1261 Data Manager può superare i normali controlli di accesso del dispositivo. Se il web server è esposto, un attaccante può rubare token di autorizzazione e usarli per ottenere il controllo amministrativo, quindi non si tratta solo di un fastidioso bug di parsing.
1 fonte · 14 mag
CVSS 9.1 CRITICAL: the net/http package improperly accepts a bare LF as a line terminator in chunked data chunk-size lines. EPSS 0.8% (55º percentile).
CISA Advisories
Siemens SENTRON 7KT PAC1261 Data Manager | CISA
Siemens SENTRON 7KT PAC1261 Data Manager Summary The web server in SENTRON 7KT PAC1261 Data Manager Before V2.1.0 contains a request smuggling vulnerability in the Go Project's net/http package that could allow an attacker to retrieve authorization tokens that can be used to gain…
originalePart of the PlainSec briefing for 2026-05-14
Every edition of this story: Request Smuggling Consente agli Attaccanti di Prendere il Controllo dei Data Manager Siemens