Feb 18, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Digitaldruid Hoteldruid: public exploit or PoC linked (RCE)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2021-43062 Fortinet Fortimail XSS

  • Public exploit or PoC available
  • Exploit activity linked

Fortinet Fortimail XSS now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2022-22909 Digitaldruid Hoteldruid RCE

  • Public exploit or PoC available
  • Exploit activity linked
  • Remote code execution exposure

Digitaldruid Hoteldruid RCE now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2022-25130 Totolink T10 Firmware Command Injection

  • CVSS 9.8

New critical Totolink T10 Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2022-0441 Exploit

The MasterStudy LMS WordPress plugin before 2.7.6 does to validate some parameters given when registering a new account, allowing unauthe...

CVE-2022-22909 Exploit

HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a cr...

CVE-2021-43062 Exploit

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, ver...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-29655 CVSS 9.8

Pexip Infinity Connect before 1.8.0 omits certain provisioning authenticity checks.

CVE-2021-29656 CVSS 9.8

Pexip Infinity Connect before 1.8.0 mishandles TLS certificate validation.

CVE-2022-25130 CVSS 9.8

A command injection vulnerability in the function updateWifiInfo of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B202110...

CVE-2022-25131 CVSS 9.8

A command injection vulnerability in the function recvSlaveCloudCheckStatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu....

CVE-2022-25132 CVSS 9.8

A command injection vulnerability in the function meshSlaveDlfw of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015...

CVE-2022-25133 CVSS 9.8

A command injection vulnerability in the function isAssocPriDevice of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211...

CVE-2022-25134 CVSS 9.8

A command injection vulnerability in the function setUpgradeFW of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211015...

CVE-2022-25135 CVSS 9.8

A command injection vulnerability in the function recv_mesh_info_sync of TOTOLINK Technology router T6 V3_Firmware T6_V3_V4.1.5cu.748_B20...

CVE-2022-25136 CVSS 9.8

A command injection vulnerability in the function meshSlaveUpdate of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20211...

CVE-2022-25137 CVSS 9.8

A command injection vulnerability in the function recvSlaveUpgstatus of TOTOLINK Technology routers T6 V3_Firmware T6_V3_V4.1.5cu.748_B20...

View critical disclosures

cvelogic Threat Intelligence