Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

CVE-2026-55637: genieacs-mcp DNS rebinding vulnerability

genieacs-mcp versions prior to 0.3.2 create an unauthenticated HTTP listener on 127.0.0.1:8080 that does not validate Host or Origin headers, allowing DNS rebinding attacks to expose or modify CPE management state through GenieACS operations.

Disclosed 25 August 2026 · Record updated 13 September 2026

Impact

Successful exploitation can expose or modify CPE management state including device reboots, firmware tasks, TR-069 parameter changes, presets, provisions, tags, connection requests, and task operations.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-55637