Back to News & Press

Press Release

Searchlight Cyber Discloses Critical Remote Command Execution Vulnerability in ETQ Reliance

Share on social

July 22, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Searchlight Cyber Discloses Critical Remote Command Execution Vulnerability in ETQ Reliance

Vulnerabilities in the popular quality management software could expose highly sensitive data

Brisbane, Australia, July 22, 2025

The Assetnote Security Research Team at Searchlight Cyber has uncovered a series of vulnerabilities in the quality management platform ETQ Reliance. In particular, the ability to access an internal “SYSTEM” account and escalate through a Remote Code Execution (RCE) vulnerability could allow an attacker to expose the stored data, which - by the nature of the application - is likely to be sensitive. All vulnerabilities were responsibly disclosed and have been patched by ETQ Reliance.

ETQ Reliance is a system for centralized document and forms management. Despite being fairly popular, it has not received much attention from security researchers - no CVEs had been registered to the product prior to the publication of this research. Searchlight's security researchers investigated the software because of the potential risk inherent in thousands of documents being exposed to the internet.

In total, four CVEs were disclosed, with the technical information on how the vulnerabilities were discovered detailed in the Assetnote Security Research Center:

  • CVE-2025-34140 - An authentication bypass vulnerability, where requests containing the suffix `;localized-text` are allowed unauthenticated access to sensitive endpoints.
  • CVE-2025-34141 - A stored cross-site scripting (XSS) vulnerability in the `SQLConverterServlet`.
  • CVE-2025-34142 - A XML External Entity (XXE) injection vulnerability via the /resources/sessions/sso endpoint.
  • CVE-2025-34143 - An authentication bypass vulnerability that allows login as the privileged SYSTEM user by appending a space character to the username field. This leads to remote command execution after bypassing authentication.

The last of these is a relatively straightforward bypass in the login screen, which allowed the researchers to access an internal “SYSTEM” account. This vulnerability could be escalated to Remote Command Execution, meaning any unauthenticated attacker can completely take over an ETQ Reliance instance, including leaking all data.

Shubham Shah, SVP of Research and Engineering at Searchlight Cyber commented: “Some vulnerabilities are simpler than others. A complex exploit is not always required to compromise software. By typing a single space in ETQ Reliance's login screen, we achieved full access to the SYSTEM account, which could quite easily be escalated to Remote Code Execution. These vulnerabilities had the potential to lead to data leaks of sensitive material.”

Searchlight Cyber's security research team continues to perform novel zero-day and N-day security research to ensure maximum coverage and care for its customers' attack surfaces. All research is integrated into its Attack Surface Management platform, Assetnote, which continuously monitors, detects, and proves the exploitability of exposures before threat actors can use them.

ENDS

About Searchlight Cyber

Searchlight Cyber was founded in 2017 with a mission to stop threat actors from acting with impunity. Its External Cyber Risk Management Platform helps organizations to identify and protect themselves from emerging cybercriminal threats with Attack Surface Management and Threat Intelligence tools designed to separate the signal from the noise. It is used by some of the world's largest enterprises, government and law enforcement agencies, and the Managed Security Service Providers at the forefront of protecting customers from external threats. Find out more at www.slcyber.io.

Related Press Releases

Searchlight Cyber Launches Preemptive Threat Exposure Management Platform to Help Organizations Outpace AI-Accelerated Attacks

Press Release

Read press release

August 12, 2026

Searchlight Cyber Launches Preemptive Threat Exposure Management Platform to Help Organizations Outpace AI-Accelerated Attacks

Searchlight Cyber Appoints Paul Ciesielski as Chief Revenue Officer

Press Release

Read press release

June 11, 2026

Searchlight Cyber Appoints Paul Ciesielski as Chief Revenue Officer

Searchlight Cyber Named a Finalist at the 2026 Cyber Risk Awards

Press Release

Read press release

April 27, 2026

Searchlight Cyber Named a Finalist at the 2026 Cyber Risk Awards

Searchlight Cyber Report: Ransomware Groups Claimed Record Number of Victims in 2025 with 30% Annual Increase

Press Release

Read press release

February 17, 2026

Searchlight Cyber Report: Ransomware Groups Claimed Record Number of Victims in 2025 with 30% Annual Increase

Searchlight Cyber Appoints Michael Gianarakis as CEO

Press Release

Read press release

February 4, 2026

Searchlight Cyber Appoints Michael Gianarakis as CEO

Searchlight Cyber Launches Ransomware File Explorer to Enable Pre-Emptive Detection of Leaked Data

Press Release

Read press release

January 22, 2026

Searchlight Cyber Launches Ransomware File Explorer to Enable Pre-Emptive Detection of Leaked Data

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient