Research
Jun 14, 2023
TLDR; We began our work on Samsung immediately after the release of the Pwn2Own Toronto 2022 target list.
In this article, we will dive into the details of an …
ByNguyễn Tiến Giang (Jang)
Research
Apr 28, 2023
Introduction While analyzing CVE-2022-41082, also known as ProxyNotShell, we discovered this vulnerability which we have detailed in this blog. However, for a …
ByNguyễn Tiến Giang (Jang)
Research
Mar 03, 2023
Summary A command injection vulnerability exists in CS-Cart’s HTML to PDF converter (https://github.com/cscart/pdf) allowing unauthenticated attackers to …
ByNgo Wei Lin
Research
Feb 24, 2023
Upon finding the vulnerability, our team member, Ngo Wei Lin (@Creastery), immediately reported it to the Microsoft Security Response Center (MSRC) on 19th …
ByNgo Wei Lin
Research
Feb 22, 2023
STAR LABS SG PTE. LTD. (STAR Labs) announced today that it has become a CVE Numbering Authority (CNA) for the Common Vulnerabilities and Exposures (CVE®) …
BySTAR Labs SG Pte. Ltd.
Research
Feb 17, 2023
Background Lately, my focus has been on discovering any potential vulnerabilities in KEPServerEX. KEPServerEX is the industry’s leading connectivity …
ByLê Hữu Quang Linh
Research
Feb 16, 2023
Introduction In this post, one of our recent intern, Wang Hengyue (@w_hy_04) was given the task to analyse CVE-2021-20617 & CVE-2021-20618 in acmailer since …
ByWang Hengyue
Research
Dec 21, 2022
As part of my internship at STAR Labs, I conducted n-day analysis of CVE-2020-6418. This vulnerability lies in the V8 engine of Google Chrome, namely its …
ByDaniel Toh Jing En
Research
Dec 06, 2022
Background Some time ago, we were playing with some Netgear routers and we learned so much from this target.
However, Netgear recently patched several …
ByVu Thi Lan, Nguyễn Hoàng Thạch
Research
Dec 06, 2022
Introduction CVE-2021-38003 is a vulnerability that exists in the V8 Javascript engine. The vulnerability affects the Chrome browser before stable version …
ByBruce Chen