Posted by disclosure via Fulldisclosure on Sep 26 0day Rubbish Research Team is publicly disclosing a vulnerability in Logo Netsis NetOpenX REST 2.0.6.9 (also distributed as Netsis Nox REST), the REST API gateway of the Netsis enterprise ERP suite. Type: unauthenticated SQL injection in the OAuth 2.0 token endpoint leading to operating-system command execution via SQL Server xp_cmdshell (CWE-89, CWE-306, CWE-78).
[0day-rubbish] Netsis NetOpenX REST 2.0.6.9 Unauthenticated SQL injection to xp_cmdshell SYSTEM command execution (9.8)
About this summary. This is a short, independently written summary of an article first published by Full Disclosure. Cyber Security News did not report or verify the underlying story. Read the original: https://seclists.org/fulldisclosure/2026/Sep/78
Source attribution: headline and facts are from Full Disclosure (seclists.org). Summary method: excerpt of the source description. See our source attribution policy.
