VYPR
AI Brief2026-07-07· generated Jul 7, 2026

NVK iBSG, Vinchin Backup Face Critical Vulnerabilities

Critical flaws in NVK iBSG, Vinchin Backup, and Pentaminds CuroVMS expose systems to command injection, default credential abuse, and data leaks.

N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 is affected by multiple critical vulnerabilities, including OS command injection (CVE-2023-39809), a hardcoded root password (CVE-2023-39808), and SQL injection (CVE-2023-39807). These flaws allow for privilege escalation and unauthorized access, posing a significant risk to systems running this software. The command injection vulnerability is particularly concerning as it can be exploited remotely via crafted input to the system_hostname parameter. The hardcoded password bypasses authentication entirely for SSH access. The SQL injection targets user registration, potentially leading to data breaches or further system compromise.

Vinchin Backup & Recovery v7.2 suffers from a critical vulnerability due to default root credentials (CVE-2024-22902). This misconfiguration allows any attacker with network access to gain complete administrative control over the backup system. Such access could enable attackers to disable backups, delete backup data, or use the compromised system as a pivot point for further network intrusion. Organizations relying on Vinchin for data protection are at severe risk if this default credential is not immediately changed.

Pentaminds CuroVMS v2.0.1 has been found to contain exposed credentials (CVE-2024-40583) and exposed sensitive information (CVE-2024-40582). While the specifics of the exposed information are not detailed, the presence of exposed credentials suggests a high risk of unauthorized access and potential data breaches. The exposed sensitive information could include customer data, system configurations, or other proprietary details, depending on the nature of the CuroVMS application.

Several vulnerabilities have been disclosed in HdrHistogram versions up to 2.2.2, affecting various components and functions. These include issues related to improper input validation (CVE-2026-56140), null pointer dereferences (CVE-2026-14790 in GPAC 26.02.0), and potential denial-of-service conditions through use-after-free (CVE-2026-14788 in radare2). While many of these are rated low severity, they highlight potential weaknesses in widely used libraries that could be chained for more significant attacks. The Apache Camel AWS SNS Component is also noted for defense-in-depth hardening due to improper input validation.

Synthesized by Vypr AI
NVK iBSG, Vinchin Backup Face Critical Vulnerabilities · VYPR