# link click (blogs) — RSS Amplifier

Recent posts from the 1 feeds in the RSS Amplifier directory that cover link click.

Page: <https://rssamplifier.com/topics/link-click/blogs>  
Feed: <https://rssamplifier.com/topics/link-click/blogs.md>

---

## [Rooting Home Assistant through MeshCore: XSS attacks with a LoRa node name](https://mxsasha.eu/posts/meshcore-xss-home-assistant/)

_2026-06-03 · Sasha Romijn_

A crafted MeshCore node name could compromise any Home Assistant instance running meshcore-card as soon as someone viewed a dashboard with that card. MeshCore relays through repeaters, so the attacker did not need to be in radio range of the target itself, only of any node that could forward to it.

## [RIPE NCC session fixation: poaching logins with an Atlas probe](https://mxsasha.eu/posts/ripe-ncc-session-fixation/)

_2026-05-28 · Sasha Romijn_

RIPE NCC&rsquo;s single sign-on did not rotate session tokens on login, leaving 12000 Atlas probe hosts in a position to compromise other RIPE NCC users&rsquo; logins. A single link click planted a session token in a target&rsquo;s browser. When that target next logged in to a RIPE NCC service, possibly much later, the attacker could access their account. An XSS variant did the same regardless of…

## [1000 third parties could have stolen RIPE NCC session tokens - by design](https://mxsasha.eu/posts/ripe-ncc-sso-cookie-exposure/)

_2026-05-06 · Sasha Romijn_

The RIPE NCC made its all-powerful single sign-on tokens available to over 1000 third parties. From a single link click, any logged-in RIPE NCC user would leak their session token. That token grants full access to the RPKI Dashboard, the RIPE Database, and the member portal. RPKI and the Database govern internet routing for Europe, the Middle East, and Central Asia. This access could be made…

## [Inside a 14-month responsible disclosure with the RIPE NCC](https://mxsasha.eu/posts/ripe-ncc-disclosure-retrospective/)

_2026-04-29 · Sasha Romijn_

This post covers the disclosure process for the vulnerabilities described in my RPKI exploit chain , through RIPE NCC&rsquo;s Responsible Disclosure Policy . Update 2026-06-10 : RIPE NCC published their own retrospective on this disclosure: What We Learned from a Multi-Service Vulnerability Disclosure , by their CISO Eleonora Petridou. What went well RIPE NCC engaged in good faith throughout. All…

## [Taking down a European network with a TLS certificate: my RIPE NCC RPKI exploit chain](https://mxsasha.eu/posts/ripe-ncc-rpki-exploit-chain/)

_2026-04-29 · Sasha Romijn_

One click on a malicious, but not suspicious, link. That is all it could take for a network operator to get disconnected from the internet, through a chain of vulnerabilities I discovered. From that single click, I could fully control their routing authorisations in a RIPE NCC portal, telling the rest of the internet not to accept their routes. I could also hijack all their RIPE Database objects,…

## [Root from the parking lot: OpenWrt XSS through SSID scanning (CVE-2026-32721)](https://mxsasha.eu/posts/openwrt-ssid-xss-to-root/)

_2026-03-19 · Sasha Romijn_

Lately, I&rsquo;ve been experimenting with unusual XSS vectors. XSS (cross-site scripting) allows an attacker to execute arbitrary javascript in another user&rsquo;s browser session. Sometimes the result is merely entertaining, sometimes the result is: Dear Sasha, excellent (and terrible) find! A crafted wifi SSID could lead to an XSS in the OpenWrt admin interface, if an admin opened the nearby…

