An ed-tech company providing K-12 curriculum has been linked to severe security vulnerabilities, including remote code execution flaws that potentially exposed thousands of school computers to malicious attacks.
Key Points
- The company's web-based C programming IDE included a local websocket server that allowed arbitrary code execution without authentication.
- Security flaws were exacerbated by the server binding to 0.0.0.0, making local machines vulnerable to remote commands from any device on the same network.
- Additional discoveries included a cookie-stealing exploit and a server-side code injection vulnerability that exposed unencrypted credit card transaction records.
- Despite these critical security failures, the company remains operational and was recently featured on TIME’s list of top American ed-tech companies.
- The founder, a former mechanical engineering professor, reportedly failed to notify school districts of the risks after implementing silent patches.