#
SUID
2 posts
Enigma — NFS credential leak, OpenSTAManager RCE, and OliveTin command injection to root
Unauthenticated NFS share leaks employee credentials → webmail credential reuse → OpenSTAManager RCE via unrestricted file upload → bcrypt hash cracking → OliveTin argument injection as root → SUID bash.
HTB Reactor: CVE-2025-55182 + Node.js Debug RCE
A critical RCE vulnerability in Next.js React Server Components (CVE-2025-55182) provides initial access. A misconfigured Node.js debugger bound to localhost enables privilege escalation to root.