> PwnFuzz Labs
  • Home
  • 1Day Breakdowns
  • About
  • #The Cryptographic Blind Spot: Sante PACS Server's Decryption Overflow Unveiled
    Jul 21, 2025 D4mianWayne 14 min read
    This article contains a full breakdown of a stack-based buffer overflow vulnerability found in Sante PACS Server version before 4.2.0 (Credits: Tenable Research). The whole application is built on top of the C, meaning we will deal with full reverse engineering, IDA pseudocode, disassemblers and debugger shenanigans.
  • #CVE 2025-2825 - CrushFTP Authentication Bypass Analysis
    Mar 30, 2025 D4mianWayne 11 min read
    Comprehensive analysis of CVE-2025-2825, a critical authentication bypass vulnerability in CrushFTP. Technical deep dive into the root cause of the vulnerability, patch analysis and exploitation process.
  • #Exploring Recent CVEs in HPE Insight Remote Support
    Jan 8, 2025 D4mianWayne 10 min read
    In this post, we’ll delve into two vulnerabilities recently discovered in the HPE Insight Remote Support (IRS) application, versions prior to v7.14.0.629. These vulnerabilities—CVE-2024-53675 (unauthenticated XXE vulnerability) and CVE-2024-53676 (Remote Code Execution, or RCE vulnerability)—pose significant security risks, allowing unauthorized access and arbitrary code execution on vulnerable systems.
  • #CVE 2024-37397 - Ivanti Endpoint Manager XXE Vulnerability
    Nov 24, 2024 D4mianWayne 14 min read
    This blog provides an in-depth analysis of the exploitation process for an unauthenticated External XML Entity (XXE) vulnerability in Ivanti Endpoint Manager, identified as CVE-2024-37397.
1 2 Next →

Recent Posts

#The Cryptographic Blind Spot: Sante PACS Server's Decryption Overflow Unveiled
#CVE 2025-2825 - CrushFTP Authentication Bypass Analysis
#Exploring Recent CVEs in HPE Insight Remote Support
© 2025 PwnFuzz Labs. All rights reserved.
Follow PwnFuzz on Twitter Go to PwnFuzz's GitHub repo