Threat Intelligence Report
3 VulnerabilitiesExecutive Summary
The most severe security findings today have been identified in a range of software and hardware, including IBM Cognos Analytics, Digigram PYKO-OUT AoIP devices, Honeywell MB-Secure alarm panels, WSO2 API Manager, Windows Deployment Services, and OttoKit WordPress plugin. The urgency of these vulnerabilities varies, but they all require immediate attention due to their impact and the potential for exploitation.
IBM Cognos Analytics has critical vulnerabilities that demand urgent patching. Digigram PYKO-OUT AoIP devices are exposed to attacks due to missing default password, which may grant unauthorized access to malicious actors. Honeywell's MB-Secure alarm panels have been compromised by a critical vulnerability identified as CVE-2025-2605, scoring a staggering 9.9 on the CVSS scale. Another critical XXE vulnerability, CVE-2025-2905 with a CVSS score of 9.1, has been found in WSO2 API Manager.
An unauthenticated DoS vulnerability has also been discovered that can crash Windows Deployment Services; unfortunately, there is currently no patch available. OttoKit WordPress plugin was identified with a critical flaw, CVE-2025-27007, that is already being exploited after disclosure, putting over 100,000 sites at risk. This situation highlights the importance of timely patching following vulnerability disclosure to prevent potential exploits.
Furthermore, Microsoft has announced that it will stop Skype and delete user data in 2026, which may have implications for user privacy and data storage. Google has also released Android updates to patch the recently attacked FreeType vulnerability, reinforcing the need for regular software updates to maintain security.
High Priority Threats
Critical Vulnerabilities
An XML External Entity (XXE) vulnerability exists in the gateway component of WSO2 API Manager due to insufficient validation of …
CVSS: 9.1Incorrect Privilege Assignment vulnerability in Brainstorm Force SureTriggers allows Privilege Escalation.This issue affects SureTriggers: from n/a through 1.0.82.
CVSS: 9.8Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. …
CVSS: 9.9High Impact Threats
Detailed Analysis
Related Vulnerabilities
Description:
An XML External Entity (XXE) vulnerability exists in the gateway component of WSO2 API Manager due to insufficient validation of XML input in crafted URL paths. User-supplied XML is parsed without appropriate restrictions, enabling external entity resolution. This vulnerability can be exploited by an unauthenticated remote attacker to read files from the server’s filesystem or perform denial-of-service (DoS) attacks. * On systems running JDK 7 or early JDK 8, full file contents may be exposed. * On later versions of JDK 8 and newer, only the first line of a file may be read, due to improvements in XML parser behavior. * DoS attacks such as "Billion Laughs" payloads can cause service disruption.
Affected Products
- WSO2 WSO2 API Manager
Description:
Incorrect Privilege Assignment vulnerability in Brainstorm Force SureTriggers allows Privilege Escalation.This issue affects SureTriggers: from n/a through 1.0.82.
Affected Products
- Brainstorm Force SureTriggers
Description:
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. This issue affects MB-Secure: from V11.04 before V12.53 and MB-Secure PRO from V01.06 before V03.09.Honeywell also recommends updating to the most recent version of this product.
Affected Products
- Honeywell MB-Secure