<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>AutoXCyber Research</title>
  <subtitle>Offensive-security research, OSINT investigations, CTF writeups and audit findings.</subtitle>
  <link rel="self" type="application/atom+xml" href="https://autoxcyber.com/feed.xml"/>
  <link rel="alternate" type="text/html" href="https://autoxcyber.com/blog/"/>
  <updated>2026-07-29T09:00:00.000Z</updated>
  <id>https://autoxcyber.com/</id>
  <icon>https://autoxcyber.com/favicon.svg</icon>
  <author><name>pondzik</name><email>contact@autoxcyber.com</email><uri>https://autoxcyber.com/</uri></author>
  <rights>© 2026 AutoXCyber</rights>
  <entry>
    <title>CVE-2024-3955: command injection in CraftBeerPi 4</title>
    <link rel="alternate" type="text/html" href="https://autoxcyber.com/blog/cve-2024-3955-craftbeerpi/"/>
    <id>https://autoxcyber.com/blog/cve-2024-3955-craftbeerpi/</id>
    <published>2026-07-29T09:00:00.000Z</published>
    <updated>2026-07-29T09:00:00.000Z</updated>
    <author><name>pondzik</name></author>
    <summary type="text">A brewing controller for the Raspberry Pi drops a URL path segment straight into os.system, inside a double-quoted shell string. Command substitution needs no quote to break out — and systemd runs it as root.</summary>
    <category term="Vulnerability Research"/>
    <category term="Disclosure"/>
    <category term="IoT"/>
  </entry>
</feed>
