Public advisories disclosed multiple severe vulnerabilities in Square Box Systems CatDV Server 10.7.8, including a pre-authentication root remote code execution chain, hardcoded/default administrator credentials, and an authenticated root RCE through property injection. The most serious issue allows an unauthenticated attacker to reach code execution as root by abusing an RMI connect(null) path, weak authorization around saveSettings, and execution of an attacker-controlled catdv.aaftoolPath during AAF export; researchers reported dynamic verification showing uid=0(root) on successful exploitation.
Separate advisories said CatDV Server can also expose the built-in admin account with a factory-default empty password, enabling administrative access where defaults were not changed. In addition, an authenticated administrator can reportedly achieve root command execution directly by injecting JVM properties without restarting the server. The vulnerabilities and proof-of-concept details were published by the 0day Rubbish Research Team, increasing the risk of immediate exploitation against exposed or poorly configured CatDV deployments.

Map this exposure pattern across your cloud, code, and identities.
2 events from the most recent confirmed update back to the earliest known activity.
A Full Disclosure mailing list post publicly disclosed the three severe CatDV Server 10.7.8 vulnerabilities, including the pre-authentication root RCE chain, hardcoded/default admin credentials, and authenticated root RCE. The post stated that successful exploitation was dynamically verified to achieve uid=0(root) and pointed to public advisories and PoC code.
On 0day-rubbish.com, the 0day Rubbish Research Team published advisories covering three vulnerabilities in Square Box Systems CatDV Server 10.7.8: a factory-default empty admin password issue, an authenticated root RCE via aaftoolPath property injection, and an unauthenticated RMI-based root RCE chain. The disclosures included technical analysis and proof-of-concept material referenced by the sources.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
4 references tracked. Mallory keeps watching after this page renders.
seclists.org
Open source0day-rubbish.com
Open source0day-rubbish.com
Open source0day-rubbish.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.