logo

Academic Exposure: The Unpatched Flaw Siphoning Student Data from DRC INSIGHT

ID: ad7d3a49-86d3-5adc-9406-bcf3e9665cc4

STIX ID: report--ad7d3a49-86d3-5adc-9406-bcf3e9665cc4

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Ddos

...
...

A critical vulnerability (CVE-2026-5756) in DRC INSIGHT's Central Office Services component exposes the /v0/configuration administrative endpoint without authentication, allowing any device on the same network to overwrite configuration JSON. An attacker could redirect student data and audio to an attacker-controlled server, force HTTPS traffic through a malicious proxy to intercept communications, or crash the service to halt exams; no patch is available and administrators are advised to isolate the server, firewall the endpoint, monitor outbound traffic, and verify config integrity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.