Trustwave SpiderLabs Security Advisory TWSL2025-002: Vulnerabilities in Quadient DS-700 iQ folder inserter Published: 09/29/2025 Version: 1.0 Vendor: Quadient [https://mail.quadient.com/] Product: DS-700 iQ Version affected: Unknown Product description: The Quadient DS-700 iQ is a high-volume folder-inserter machine designed for automating the process of assembling, folding, and inserting mailpieces into envelopes for large mailing operations. It features a modular design that can handle complex mailing jobs, supports multiple feeders and enclosures, and offers integration with barcode/OMR/2D scanning for document integrity and sorting. The DS-700 iQ is particularly suited for industries that require high-volume mail processing, such as billing, banking, and direct marketing. Finding X: Improper Privilege Management in Quadient DS-700 iQ folder inserter *****Credit: John Jackson of Trustwave CVE: PENDING CWE: 284 Description of Finding The Quadient DS-700 iQ folder inserter runs its underlying Windows operating system under a local administrator account named "neopost." Given that this account is a member of the local Administrators group, it has complete and unrestricted access to the device. An attacker who gains physical or logical access to the device could exploit the default configuration to escape the restricted interface (kiosk mode breakout) and obtain full administrative privileges on the operating system. This vulnerability could allow attackers to disable security controls, install malware, dump credentials, or install network interfaces to establish outbound connections, significantly compromising the security posture of the environment. Proof of Concept <--See Picture--> Vendor Response: None Remediation Steps: Pending Revision History: 06/11/2025 - Initial outreach to vendor (security@quadient.com) 06/23/2025 - Follow up to vendor for no response 07/03/2025 - Additional attempts at vendor contact, including alternative email addresses 07/09/2025 - Additional attempts at vendor contact, including "Contact Us" form 07/09/2025 - Replied to request for additional information from a Quadient repair group address. No further replies. 07/10/2025 - Vendor reply to "Contact Us" submission stating "Kindly note that our organization does not accept unsolicited proposals or solicitations." 07/15/2025 - 6th attempt at vendor contact with no response 08/07/2025 - Final attempt at vendor contact with no reply 09/29/2025 - Advisory published About Trustwave: Trustwave helps businesses fight cybercrime, protect data and reduce security risk. With cloud and managed security services, integrated technologies and a team of security experts, ethical hackers and researchers, Trustwave enables businesses to transform the way they manage their information security and compliance programs. More than three million businesses are enrolled in the Trustwave TrustKeeper® cloud platform, through which Trustwave delivers automated, efficient and cost-effective threat, vulnerability and compliance management. Trustwave is headquartered in Chicago, with customers in 96 countries. For more information about Trustwave, visit https://www.trustwave.com. About Trustwave SpiderLabs: SpiderLabs(R) is the advanced security team at Trustwave focused on application security, incident response, penetration testing, physical security and security research. The team has performed over a thousand incident investigations, thousands of penetration tests and hundreds of application security tests globally. In addition, the SpiderLabs Research team provides intelligence through bleeding-edge research and proof of concept tool development to enhance Trustwave's products and services. https://www.trustwave.com/spiderlabs Disclaimer: The information provided in this advisory is provided "as is" without warranty of any kind. Trustwave disclaims all warranties, either express or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Trustwave or its suppliers be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages, even if Trustwave or its suppliers have been advised of the possibility of such damages. Some states do not allow the exclusion or limitation of liability for consequential or incidental damages so the foregoing limitation may not apply