CVE-2021-3854
critical
📛 Threat Title
CVE-2021-3854
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Glox Technology Useroam Hotspot allows SQL Injection. This issue affects Useroam Hotspot: before 5.1.0.15.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
5.1.0.15
IOC database
- Type
- ipv4
- Value
5.1.0.15- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat CVE-2021-3854
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (3)
-
NVD detail: CVE-2021-3854
NVD Recent CVEs
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Glox Technology Useroam Hotspot allows SQL Injection. This issue affects Useroam Hotspot: before 5.1.0.15.
- iletisim@usom.gov.tr NVD Recent CVEs
- iletisim@usom.gov.tr NVD Recent CVEs
Remediations (8)
-
web:app.opencve.io
Remediation No vendor fix or workaround currently provided. OpenCVE Recommended Actions Apply the latest GitHub Enterprise Server patch (3.19.4 or later) to fix the push option injection flaw. Temporarily revoke or restrict push permissions for untrusted users until a patch is applied.
-
web:nvd.nist.gov
An official website of the United States government Here's how you know
-
web:thecodersblog.com
The Patch and Mitigation : GitHub's Response and Developer Actions GitHub's Remediation Upon receiving the bug bounty report from Wiz researchers on March 4, 2026, GitHub acted rapidly. Within hours, they validated the finding, identified the root cause, and deployed a fix to GitHub.com and Enterprise Cloud environments.
-
web:thecyberexpress.com
CVE -2026- 3854 RCE vulnerability in GitHub Enterprise Server lets attackers run code via git push. Patch now to secure affected systems.
-
web:www.bleepingcomputer.com
In early March, GitHub patched a critical remote code execution vulnerability ( CVE -2026- 3854 ) that could have allowed attackers to access millions of private repositories.
-
web:www.msn.com
A critical remote code execution flaw in GitHub was patched by Microsoft in roughly two hours after public disclosure, closing what security researchers are calling the platform's most severe ...
-
web:www.sentinelone.com
CVE -2026- 3854 is a remote code execution vulnerability in GitHub Enterprise Server. Learn about its impact, affected versions, and mitigation methods.
-
web:www.wiz.io
Securing GitHub: Wiz Research uncovers Remote Code Execution in GitHub.com and GitHub Enterprise Server ( CVE -2026- 3854 ) Details on CVE -2026- 3854 : A critical flaw in GitHub's internal git infrastructure enabling RCE on GitHub.com and GitHub Enterprise Server.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.