@tychotithonus@infosec.exchange
2026-09-23 13:12 UTC
Pre-auth RCE in Shrubbery tac_plus, common TACACS+ implementation. And perhaps underneath a number of commercial solutions that provide network authentication.
No CVE yet. Goes back 25 years.
"Shrubbery fixed it in F4.0.4.32, published on 21 September, and the Facebook fork is archived, so it will not be fixed at all."
Write-up by discoverer:
https://www.elttam.com/blog/att-cking-tacacs-to-pwnyour-network-via-a-pre-auth-rce
Patched source:
https://shrubbery.net/pub/tac_plus/
Edit: note that the SHA256 for the patched download has a stale timestamp, so may be outdated. At this writing, my download SHA256 is ee3e403a079c75cad13ce9e451c1af0115b0647142765bbd85e60d7a9f3f3fd2
Edit 2: I started an IFIN post here, if you learn about which products are affected, please contribute!
https://ifin.network/t/cve-pending-pre-auth-format-string-bug-in-tac-plus-shrubbery-networks/859
At this writing, none of the distros are patched. OpenWrt confirmed uses Shrubbery. Commercial products unclear.
#TACACS #tacplus
Replies (1)
-
@tychotithonus@infosec.exchange 2026-09-23 15:57
Also it's kinda wild that Shrubbery: only provides an ftp:// URI to link to their downloadsdoesn't automate creating their SHA256doesn't provide links to download old versions of the software -- but here's a Wayback to .28: https://web.archive.org/web/20250302064901/https://shrubbery.net/pub/tac_plus/tacacs-F4.0.4.28.tar.gz