Skip to content

Commit bf79755

Browse files
authored
Disclosing CVE-2025-2894 (#213)
Signed-off-by: Tod Beardsley <[email protected]> (he smells)
1 parent ddedb83 commit bf79755

File tree

2 files changed

+110
-7
lines changed

2 files changed

+110
-7
lines changed

content/cve.md

Lines changed: 8 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ Because AHA! is a research organization, we will also accept vulnerability repor
3131

3232
### Out of Scope
3333

34-
- Assets or other equipment not owned by parties which **are already** participating as a [CVE Numbering Authority].
34+
- Assets or other equipment not owned by parties which **are already** participating as a [CVE Numbering Authority].
3535

3636
Vulnerabilities discovered or suspected in out-of-scope systems should be reported to the appropriate vendor or applicable authority.
3737

@@ -56,9 +56,9 @@ In participating in our vulnerability disclosure program in good faith, we ask t
5656
- Perform testing only on in-scope systems, and respect systems and activities which are out-of-scope;
5757
- If a vulnerability provides unintended access to data: Limit the amount of data you access to the minimum required for effectively demonstrating a Proof of Concept; and cease testing and submit a report immediately if you encounter any user data during testing, such as Personally Identifiable Information (PII), Personal Healthcare Information (PHI), credit card data, or proprietary information;
5858
- You should only interact with test accounts you own or with explicit permission from the account holder; and
59-
- Do not engage in extortion.
59+
- Do not engage in extortion.
6060

61-
### Official Channels
61+
### Official Channels
6262

6363
Please report security issues affecting AHA! via [[email protected]](mailto:[email protected]), providing all relevant information. The more details you provide, the easier it will be for us to triage and fix the issue.
6464

@@ -97,8 +97,8 @@ For issues involving other parties, please see additional requirements, below. N
9797
When we publish CVEs, we will tend to use this [template], adjusted to taste.
9898

9999
| CVE | Meeting | Issue |
100-
| ---------------- | --------- | ------------------------------------------ |
101-
| [CVE-2023-0666] | 0x00c7 | **Wireshark RTPS Parsing Buffer Overflow** |
100+
| ---------------- | --------- | ------------------------------------------ |
101+
| [CVE-2023-0666] | 0x00c7 | **Wireshark RTPS Parsing Buffer Overflow** |
102102
| [CVE-2023-0667] | 0x00c7 | **Wireshark MSMMS parsing buffer overflow** |
103103
| [CVE-2023-0668] | 0x00c7 | **Wireshark IEEE-C37.118 parsing buffer overflow** |
104104
| [CVE-2023-2905] | 0x00c8 | **Cesanta Mongoose MQTT Message Parsing Heap Overflow** |
@@ -109,7 +109,8 @@ When we publish CVEs, we will tend to use this [template], adjusted to taste.
109109
| [CVE-2024-2054] | 0x00d1 | **Artica Proxy Unauthenticated PHP Deserialization** |
110110
| [CVE-2024-2055] | 0x00d1 | **Artica Proxy Unauthenticated File Manage** |
111111
| [CVE-2024-2056] | 0x00d1 | **Artica Proxy Loopback Services Remotely Accessible Unauthenticated** |
112-
| [CVE-2024-4224] | 0x00d3 | **TP-Link TL-SG1016DE XSS** |
112+
| [CVE-2024-4224] | 0x00d3 | **TP-Link TL-SG1016DE XSS** |
113+
| [CVE-2025-2894] | 0x00de | **Unitree Go1 Backdoor Control Channel |
113114

114115
## Reserved CVEs
115116

@@ -145,4 +146,4 @@ Vulnerabilities involving other parties must be either (1) presented at a regula
145146
[CVE-2024-2055]: https://korelogic.com/Resources/Advisories/KL-001-2024-003.txt
146147
[CVE-2024-2056]: https://korelogic.com/Resources/Advisories/KL-001-2024-004.txt
147148
[CVE-2024-4224]: {{< baseurl >}}cves/cve-2024-4224/
148-
149+
[CVE-2025-2894]: {{< baseurl >}}cves/cve-2025-2894/

content/cves/CVE-2025-2894.md

Lines changed: 102 additions & 0 deletions
Large diffs are not rendered by default.

0 commit comments

Comments
 (0)