<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0">
  <channel>
    <title>Critical Security — Security Today</title>
    <link>https://critical.lt/</link>
    <description>Critical Security — security assessments, research, and practical security guidance.</description>
    <language>en-US</language>
    <lastBuildDate>Sun, 04 Oct 2026 12:00:00 GMT</lastBuildDate>
    <item>
      <title>TerraMaster TNAS PC Remote Code Execution</title>
      <link>https://critical.lt/blog/terramaster-tnas-pc-remote-code-execution/</link>
      <guid isPermaLink="true">https://critical.lt/blog/terramaster-tnas-pc-remote-code-execution/</guid>
      <pubDate>Sun, 04 Oct 2026 12:00:00 GMT</pubDate>
      <description>TerraMaster TNAS PC is the Windows desktop client for managing TerraMaster network-attached storage (NAS) devices. TNAS PC 5.2.548 for Windows (built on Electron 25.9.8), and likely prior versions, contains an unauthenticated vulnerability chain that enables Remote Code Execution on Windows hosts running the application. The attack requires no authentication, no user interaction, no man-in-the-middle position, and no prior pairing with a NAS device – any host on the same local network segment can carry it out.</description>
    </item>
    <item>
      <title>ASUS GPU Tweak III Remote Code Execution</title>
      <link>https://critical.lt/blog/asus-gpu-tweak-iii-remote-code-execution/</link>
      <guid isPermaLink="true">https://critical.lt/blog/asus-gpu-tweak-iii-remote-code-execution/</guid>
      <pubDate>Sun, 04 Oct 2026 12:00:00 GMT</pubDate>
      <description>ASUS GPU Tweak III is a GPU overclocking and monitoring application for graphics cards. ASUS GPU Tweak III v2.1.8.0 for Windows, and likely prior versions, contains a vulnerability chain that enables Remote Code Execution through command injection on Windows hosts running the software with the Mobile Module service component installed. The attack requires no authentication and can be triggered from the local network or potentially from a malicious website.</description>
    </item>
    <item>
      <title>Elpako Remote Code Execution</title>
      <link>https://critical.lt/blog/elpako-remote-code-execution/</link>
      <guid isPermaLink="true">https://critical.lt/blog/elpako-remote-code-execution/</guid>
      <pubDate>Tue, 28 Jul 2026 15:30:00 GMT</pubDate>
      <description>Elpako is local cryptographic middleware software that bridges web-based signing applications to USB tokens or ID card readers via PKCS#11 and PC/SC, enabling qualified electronic signatures using hardware-backed cryptographic elements. Elpako v3.3.6 for Windows, and likely prior versions, contain a vulnerability chain that enables Remote Code Execution on Windows hosts running the Elpako Root daemon.</description>
    </item>
    <item>
      <title>TELE2 PILDYK SIM Card Registration Bypass</title>
      <link>https://critical.lt/blog/tele2-pildyk-sim-card-registration-bypass/</link>
      <guid isPermaLink="true">https://critical.lt/blog/tele2-pildyk-sim-card-registration-bypass/</guid>
      <pubDate>Mon, 17 Mar 2025 00:00:00 GMT</pubDate>
      <description>General Overview As of January 1, 2025, Lithuania has implemented mandatory registration for new prepaid SIM cards to combat fraud and criminal activities. Registration can be completed online through mobile operators’ platforms or in person at authorized stores using an official ID, such as a passport or national identity card. This measure does not affect…</description>
    </item>
    <item>
      <title>Path Traversal Vulnerability in PrestaShop &lt;8.2.0</title>
      <link>https://critical.lt/blog/path-traversal-vulnerability-in-prestashop-8-2-0/</link>
      <guid isPermaLink="true">https://critical.lt/blog/path-traversal-vulnerability-in-prestashop-8-2-0/</guid>
      <pubDate>Tue, 15 Oct 2024 00:00:00 GMT</pubDate>
      <description>In this blog post we will briefly describe a Path Traversal vulnerability in PrestaShop open-source e-commerce platform that can be used for privilege escalation. As stated on project’s Wikipedia page it is currently used by 300,000 shops worldwide. Vulnerability Description A vulnerability has been identified in PrestaShop versions below 8.2.0 (tested in 8.1.7 and 8.1.4)…</description>
    </item>
    <item>
      <title>Authorization Bypass and Mass Assignment in Pantera CRM</title>
      <link>https://critical.lt/blog/authorization-bypass-and-mass-assignment-in-pantera-crm/</link>
      <guid isPermaLink="true">https://critical.lt/blog/authorization-bypass-and-mass-assignment-in-pantera-crm/</guid>
      <pubDate>Fri, 12 Jul 2024 00:00:00 GMT</pubDate>
      <description>General Overview Critical Security discovered two critical vulnerabilities in the Pantera CRM, posing significant risks to data integrity, confidentiality, and availability. These vulnerabilities were identified in versions 401.152 and 402.072 and could allow unauthorized attackers to compromise the system. Pantera CRM is a web-based business management system designed to expedite and automate various processes, and…</description>
    </item>
    <item>
      <title>Unauthenticated Remote Code Execution and Path Traversal in LABBIS BONUS Software</title>
      <link>https://critical.lt/blog/unauthenticated-remote-code-execution-and-path-traversal-in-labbis-bonus-software/</link>
      <guid isPermaLink="true">https://critical.lt/blog/unauthenticated-remote-code-execution-and-path-traversal-in-labbis-bonus-software/</guid>
      <pubDate>Mon, 18 Sep 2023 00:00:00 GMT</pubDate>
      <description>General Overview BONUS is a software solution for payroll and time management, offered to businesses by LABBIS as a part of their paid services. An insecure method call mechanism without proper authorization checks was discovered in version 1.2.29.0 of the software. This vulnerability allows unauthenticated attackers to call arbitrary methods from the LABBIS .NET assemblies.…</description>
    </item>
    <item>
      <title>Revealing the Identity of Mark Sign Users</title>
      <link>https://critical.lt/blog/revealing-the-identity-of-mark-sign-users/</link>
      <guid isPermaLink="true">https://critical.lt/blog/revealing-the-identity-of-mark-sign-users/</guid>
      <pubDate>Sun, 04 Jun 2023 00:00:00 GMT</pubDate>
      <description>MarkSign is a solution that provides functionality of signing documents electronically. The vendor as part of its ecosystem provides “Mark Sign Software” (v1.1.0) package for Windows that enables use of USB Token or Smart Card based devices. Vulnerability in this software package enables a malicious third-party to deanonymize unsuspecting user over the WEB by means…</description>
    </item>
    <item>
      <title>Extraction of Personally Identifiable Information via eParaksts signing extension</title>
      <link>https://critical.lt/blog/extraction-of-personally-identifiable-information-via-eparaksts-signing-extension/</link>
      <guid isPermaLink="true">https://critical.lt/blog/extraction-of-personally-identifiable-information-via-eparaksts-signing-extension/</guid>
      <pubDate>Mon, 05 Sep 2022 00:00:00 GMT</pubDate>
      <description>Due to the vulnerability in the “eParaksts signing extension” (v1.1.5) it is possible to extract public certificates of Latvian electronic identity card (eID) users. This can be done by embedding a malicious JavaScript code to a website. For the attack to be successful, the victim must visit the web page hosting the malicious JavaScript code…</description>
    </item>
    <item>
      <title>How to (Correctly) Protect Fintech Apps for Android with Biometric Authentication</title>
      <link>https://critical.lt/blog/how-to-correctly-protect-fintech-apps-for-android-with-biometric-authentication/</link>
      <guid isPermaLink="true">https://critical.lt/blog/how-to-correctly-protect-fintech-apps-for-android-with-biometric-authentication/</guid>
      <pubDate>Tue, 22 Jun 2021 00:00:00 GMT</pubDate>
      <description>During numerous mobile app security assessments we faced fintech apps for Android, that had an option to protect user data with biometric authentication, but failed to implement it in a secure way leading to authentication bypass. Although the security risk is very low due to attack-specific prerequisites, such as acquiring physical access to a mobile…</description>
    </item>
    <item>
      <title>WE.LOCK: Unlocking Smart Locks with Web Vulnerabilities</title>
      <link>https://critical.lt/blog/we-lock-unlocking-smart-locks-with-web-vulnerabilities/</link>
      <guid isPermaLink="true">https://critical.lt/blog/we-lock-unlocking-smart-locks-with-web-vulnerabilities/</guid>
      <pubDate>Wed, 02 Jun 2021 00:00:00 GMT</pubDate>
      <description>WE.LOCK is a smart home access solution provider that manufactures and sells smart locks. WE.LOCK smart locks can be unlocked using a fingerprint, access codes, RFID tags, a smartphone app via Bluetooth (BLE) or the physical key supplied with a lock. In this article we are focusing on a smartphone app for Android, a mobile…</description>
    </item>
    <item>
      <title>IBM Spectrum Protect: Exploiting Legacy Authentication Protocol</title>
      <link>https://critical.lt/blog/ibm-spectrum-protect-exploiting-legacy-authentication-protocol/</link>
      <guid isPermaLink="true">https://critical.lt/blog/ibm-spectrum-protect-exploiting-legacy-authentication-protocol/</guid>
      <pubDate>Thu, 20 May 2021 00:00:00 GMT</pubDate>
      <description>We want to share details of a little-known attack vector that we have successfully exploited during numerous security audits. IBM Spectrum Protect is a backup solution that provides data protection for virtual, physical and cloud environments. The solution is based on a client-server architecture. IBM Spectrum Protect client nodes, administrative clients, and servers communicate using…</description>
    </item>
    <item>
      <title>Paradox (In)Security Systems: IP150 Internet Module Hijacking</title>
      <link>https://critical.lt/blog/paradox-insecurity-systems-ip150-internet-module-hijacking/</link>
      <guid isPermaLink="true">https://critical.lt/blog/paradox-insecurity-systems-ip150-internet-module-hijacking/</guid>
      <pubDate>Tue, 11 May 2021 00:00:00 GMT</pubDate>
      <description>Paradox Security Systems is a Canadian company manufacturing alarm systems and various security devices since 1989. One of their most popular family of products are the IP150 internet modules. They are used with their SP, MG and EVO series security alarm panels to enable control and monitoring of the security alarms over the Internet. In…</description>
    </item>
    <item>
      <title>Deanonymization Of Lithuanian E-Signature Users</title>
      <link>https://critical.lt/blog/deanonymization-of-lithuanian-e-signature-users/</link>
      <guid isPermaLink="true">https://critical.lt/blog/deanonymization-of-lithuanian-e-signature-users/</guid>
      <pubDate>Wed, 16 Sep 2020 00:00:00 GMT</pubDate>
      <description>In 2020, remote work and digital access to public services have become the new normal. Lithuanian citizens have multiple options for accessing different public services and signing documents online. In this article, we will discuss user privacy issues that our team has recently discovered in two independent e-signature solutions, which have been fixed by now.…</description>
    </item>
  </channel>
</rss>