CVE-2025-66238 is an authentication bypass using an alternate path or channel in Sunbird DCIM dcTrack affecting version 9.2.0 and earlier. According to the provided advisory content, an authenticated user who already has access to the appliance's virtual console can misuse certain remote access features exposed through that console. By abusing this alternate access path, the attacker can redirect network traffic through the appliance and potentially reach services or data on the underlying host machine that would otherwise be restricted. The issue is classified as CWE-288 and is described as remotely exploitable with low attack complexity.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.