Skip to content

Instantly share code, notes, and snippets.

View sgInnora's full-sized avatar

Feng Ning sgInnora

View GitHub Profile
@sgInnora
sgInnora / advisory_draytek_v2.md
Created April 30, 2026 08:49
DrayTek Vigor 2962 draycrond Daemon Vulnerabilities (CVE-2026-37545/42470)
# DrayTek Vigor 2962 — draycrond Daemon Command Injection and Authentication Bypass

**Vendor**: DrayTek  
**Affected**: Vigor 2962 Firmware 4.3.1 and 4.4.5.2  
**Reporter**: Feng Ning, Innora Security Research (feng@innora.ai)  
**Disclosure**: 2026-04-30  
**Note**: Vendor (Louis Hsu, DrayTek) confirmed that the latest firmware release addresses these issues.

| CVE | Type | CWE | CVSS |
@sgInnora
sgInnora / advisory_vanetza_v2.md
Created April 30, 2026 08:49
Vanetza V2X v26.02 Denial of Service (CVE-2026-37554)
# Vanetza V2X v26.02 — Denial of Service via Malformed V2X Messages

**Vendor**: Vanetza (github.com/riebl/vanetza)  
**Affected**: v26.02  
**Reporter**: Feng Ning, Innora Security Research (feng@innora.ai)  
**CVE**: CVE-2026-37554  
**CWE**: CWE-125 / CWE-476  
**CVSS**: 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)  
**Disclosure**: 2026-04-30  
@sgInnora
sgInnora / advisory_agl_v2.md
Created April 30, 2026 08:49
Automotive Grade Linux (AGL) Multiple Vulnerabilities (CVE-2026-37525/37526/37530/37531/37532/42485)

Automotive Grade Linux (AGL) — Multiple Vulnerabilities

Vendor: Automotive Grade Linux (AGL), Linux Foundation Affected: agl-service-can-low-level ≤ 17.1.12, app-framework-binder (afb-daemon) ≤ v19.90.0, app-framework-main ≤ 17.1.12 Reporter: Feng Ning, Innora Security Research (feng@innora.ai) Disclosure: 2026-04-30

CVE Component Type CWE CVSS
CVE-2026-37525 afb-daemon — supervision socket Privilege Escalation CWE-269 7.8
@sgInnora
sgInnora / advisory_automotive_v2.md
Created April 30, 2026 08:49
Automotive CAN Protocol Libraries Multiple Buffer Overflows (CVE-2026-37534 through 37541, 42467-42469)

Automotive CAN Protocol Libraries — Multiple Buffer Overflow Vulnerabilities

Reporter: Feng Ning, Innora Security Research (feng@innora.ai) Disclosure: 2026-04-30

CVE Library / Product Version Type CVSS
CVE-2026-37534 Open-SAE-J1939 ≤ b6caf884 Integer Underflow → OOB Write 9.8
CVE-2026-42467 Open-SAE-J1939 ≤ b6caf884 Stack Buffer Overflow 9.8
CVE-2026-37535 openxc/isotp-c ≤ 5a5d1924 OOB Read 7.5
@sgInnora
sgInnora / advisory_mixphp_v2.md
Created April 30, 2026 08:49
MixPHP 2.x Deserialization RCE and SQL Injection (CVE-2026-37552, CVE-2026-42471 through 42475)

MixPHP Framework 2.x ≤ 2.2.17 — Deserialization RCE and SQL Injection

Vendor: MixPHP (github.com/mix-php/mix)
Affected: 2.x ≤ 2.2.17
Reporter: Feng Ning, Innora Security Research (feng@innora.ai)
Disclosure: 2026-04-30

CVE Type CWE CVSS
CVE-2026-37552 Deserialization RCE — sync-invoke TCP server CWE-502 9.8
@sgInnora
sgInnora / advisory_v2board_v2.md
Created April 30, 2026 08:49
V2Board ≤1.7.4 Multiple Vulnerabilities (CVE-2026-37503/37504/37505)
# V2Board ≤ 1.7.4 Multiple Vulnerabilities

**Vendor**: V2Board (github.com/v2board/v2board) — unmaintained since 2023  
**Affected**: ≤ 1.7.4 (all versions; project abandoned)  
**Reporter**: Feng Ning, Innora Security Research (feng@innora.ai)  
**Disclosure**: 2026-04-30  

| CVE | Type | CWE | Location |
|-----|------|-----|----------|
@sgInnora
sgInnora / advisory_ai_deser_v2.md
Created April 30, 2026 08:49
AI/ML Framework Unsafe Deserialization: ColossalAI, Open-Sora, ModelScope, Coqui TTS, pytorch-lightning

Unsafe Deserialization in AI/ML Frameworks via torch.load() / yaml.load()

Reporter: Feng Ning, Innora Security Research (feng@innora.ai)
Disclosure: 2026-04-30

CVE Package Version Sink CVSS
CVE-2026-37562 ColossalAI ≤ 0.5.0 torch.load() 7.8
CVE-2026-37566 Open-Sora 1.3 torch.load() 7.8
CVE-2026-37567 ModelScope 2.0.0 torch.load() 300+ paths 7.8
@sgInnora
sgInnora / advisory_occt_v2.md
Created April 30, 2026 08:49
OCCT Multiple Memory Safety Vulnerabilities (CVE-2026-42476 through CVE-2026-42481)
# Open CASCADE Technology (OCCT) Multiple Memory Safety Vulnerabilities

**Vendor**: Open CASCADE SAS (dev.opencascade.org)  
**Affected**: OCCT ≤ 7.8.1, master through commit c540f316  
**Reporter**: Feng Ning, Innora Security Research (feng@innora.ai)  
**Disclosure**: 2026-04-30  

| CVE | Component | CWE | CVSS |
|-----|-----------|-----|------|
@sgInnora
sgInnora / libsndfile_advisory_v2.md
Created April 30, 2026 08:32
libsndfile IMA-ADPCM Integer Overflow in WAV/W64 Path (CVE-2026-37555)

libsndfile IMA-ADPCM Integer Overflow in WAV/W64 Path (CVE-2026-37555)

CVE: CVE-2026-37555
Affected: libsndfile ≤ 1.2.2 (latest release)
CWE: CWE-190 (Integer Overflow or Wraparound)
CVSS 3.1: 5.5 (AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H) — Local, user interaction required (open a crafted file)
Reporter: Feng Ning, Innora Security Research (feng@innora.ai)


@sgInnora
sgInnora / gist_final.md
Created April 17, 2026 11:52
Innora Security — Independent Blockchain Security Research Portfolio

Innora Security — Independent Blockchain Security Research

About

Innora Security provides independent security research and audit services for Web3 infrastructure, smart contracts, and hardware wallets. Founded by Feng Ning (CISSP), founder of Innora.ai and an early Chinese security researcher now based in Penang, Malaysia, our work starts from attacker-controlled assumptions: low-level systems vulnerability research, economic invariant analysis, and high-throughput fuzzing.

We value reproducible evidence over opinion. Our work spans the blockchain stack, from node infrastructure and hardware signing devices to high-value DeFi protocols. Our working rule is simple: No code is done until it is committed, documented, and fully reproducible.

Recent Findings