#sshnpd
Two Atsign NoPorts vulnerabilities in the sshnpd C daemon let any valid atSign identity inject an SSH key and gain unauthorized access via the relay.

#Atsign #NoPorts #SSH #Vulnerability #sshnpd
Atsign NoPorts Vulnerabilities Let Any atSign Gain SSH Access
Remote-access systems without open ports are meant to shrink the attack surface. Yet a single flaw in authorization checks can push the risk back up to the application layer. A UltraViolet Cyber researcher discovered two vulnerabilities in the sshnpd C daemon of the Atsign NoPorts platform. Together, they could have allowed the holder of any valid atSign identity to obtain unauthorized SSH access.
meterpreter.org
August 31, 2026 at 2:54 AM