Home
» Risk & Exploitation
» Daily threat intelligence
» Mar 31, 2022
Mar 31, 2022 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
Dasan Gigabit Passive Optical Network (GPON) Routers: 2 CVEs added to CISA KEV today.
8 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical active threat
CVE-2018-10561
Dasan GPON Routers Authentication Bypass
Actively exploited (CISA KEV)
Listed on CISA KEV
Authentication bypass — unauthenticated access risk
Dasan Gigabit Passive Optical Network (GPON) Routers Auth Bypass is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.
Critical exposure
CVSS 10
Remote code execution exposure
New critical Raspberrymatic RCE (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
CVE-2022-24803
Asciidoctor-include-ext is Asciidoctor’s standard include processor reimplemented as an extension.
New critical disclosure (CVSS 10) — high severity with a short public awareness window before exploit material typically surfaces.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Trend Micro Apex Central Arbitrary File Upload
Sophos Firewall Authentication Bypass
Microsoft Windows User Profile Service Privilege Escalation
QNAP NAS Improper Authorization
Dell dbutil Driver Insufficient Access Control
Dasan GPON Routers Authentication Bypass
Dasan GPON Routers Command Injection
View KEV additions
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
A Remote Code Execution (RCE) vulnerability exists in The-Secretary 2.5 via install.php.
A Remote Code Execution (RCE) vulnerability exists in Simple Client Management System 1.0 in create.php due to the failure to validate th...
An SQL Injection vulnerability exists in Sourcecodester Simple Client Management System 1.0 via the password parameter in Login.php.
D-Link DIR-645 1.03 A1 is vulnerable to Buffer Overflow.
Hospital Management System v1.0 is affected by an unrestricted upload of dangerous file type vulerability in treatmentrecord.php.
RaspberryMatic is a free and open-source operating system for running a cloud-free smart-home using the homematicIP / HomeMatic hardware...
Asciidoctor-include-ext is Asciidoctor’s standard include processor reimplemented as an extension.
Hospital Management System v1.0 was discovered to lack an authorization component, allowing attackers to access sensitive information and...
View critical disclosures
cvelogic
Threat Intelligence