,

Vulnerability Watch No44

🚨 Tenda G0 Port Mapping Flaw Enables Remote Buffer Overflow
Teams operating Tenda G0 devices should prioritize remediation or restrict management-interface exposure immediately. Public exploit code raises the likelihood of opportunistic attacks.
CVE-2026-19792 is a remotely exploitable buffer overflow in the Tenda G0 httpd web management interface, affecting the setPortMapping function in /goform/module on versions up to 20260625. Manipulating portMappingServer/porMappingtInternal/portMappingExternal can trigger the flaw. It is rated HIGH with CVSS 8.8, and a public exploit is available.
🔗 Read more 🔗
Source: NVD

🚨 Tenda G0 Static Route Bug Triggers Remote Stack Overflow
Tenda G0 administrators should treat this as high priority, especially where the management interface is remotely reachable. Apply vendor remediation when available and reduce exposure now because exploit code is public.
CVE-2026-19791 affects the Tenda G0 httpd web management interface up to version 20260625. Manipulation of staticRouteNet in the addStaticRoute function of /goform/module can cause a stack-based buffer overflow remotely. The vulnerability is rated HIGH with CVSS 8.8, and its exploit has been made public.
🔗 Read more 🔗
Source: NVD

⚠️ Tenda G0 Port Mirroring Endpoint Hit by Buffer Overflow
Organizations with affected Tenda G0 appliances should patch or mitigate promptly and keep the web management interface off untrusted networks. Public exploit availability makes delaying remediation risky.
CVE-2026-19790 is a stack-based buffer overflow in the Tenda G0 httpd Web Management Interface up to version 20260625. The flaw occurs in formSetPortMirror within /goform/module when portMirrorMirroredPorts is manipulated and can be exploited remotely. It carries a HIGH severity rating with CVSS 8.8, and a public exploit is available.
🔗 Read more 🔗
Source: NVD

🚨 Tenda AC1206 Guest Wi-Fi Handler Exposed to Remote Overflow
Owners of the affected AC1206 firmware should remediate quickly or isolate the administration interface until a fix is available. The public exploit disclosure increases near-term attack risk.
CVE-2026-19789 affects Tenda AC1206 15.03.06.23_multi_TD01 and resides in the set_wl_guest_iplist function of /goform/WifiGuestSet in the httpd web management interface. Manipulating the shareSpeed argument can trigger a stack-based buffer overflow remotely. The issue is rated HIGH with CVSS 8.8, and exploit details have been publicly disclosed.
🔗 Read more 🔗
Source: NVD

🚨 Tenda AC1206 Device Naming Flaw Enables Remote Buffer Overflow
Patch affected AC1206 devices as soon as remediation is available and restrict access to the management interface in the meantime. Public exploit availability warrants elevated urgency.
CVE-2026-19788 is a stack-based buffer overflow affecting Tenda AC1206 15.03.06.23_multi_TD01. The vulnerability is in the set_device_name function of /goform/SetOnlineDevName within the httpd web management interface and can be triggered remotely through the devName argument. It is rated HIGH with CVSS 8.8, and the exploit has been made public.
🔗 Read more 🔗
Source: NVD

🧩 W3 Total Cache Lazy Load Feature Opens Stored XSS Risk
WordPress operators using W3 Total Cache with Lazy Load Images enabled should prioritize updating and review whether untrusted comments have been submitted. Sites without that feature enabled are not exposed through the described vulnerable path.
CVE-2026-18109 is a stored cross-site scripting vulnerability in the W3 Total Cache plugin for WordPress through version 2.10.3. An unauthenticated attacker can inject scripts through the Comment Author Name when the Lazy Load Images feature is enabled, causing the payload to execute when affected pages are viewed. The flaw is rated HIGH with CVSS 7.2.
🔗 Read more 🔗
Source: NVD

💥 Baicells EG3661M LuCI Interface Vulnerable to Command Injection
Operators of affected Baicells devices should treat this as urgent because remote command injection can provide a powerful foothold. Limit LuCI exposure immediately and apply a vendor fix as soon as one becomes available.
CVE-2026-19771 affects Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA and allows OS command injection through the /cgi-bin/luci LuCI Web Interface. Manipulation of the MaxHops/Timeout/Size arguments can be exploited remotely. The vulnerability is rated HIGH with CVSS 7.2, and a public exploit is available; the vendor reportedly did not respond to the disclosure.
🔗 Read more 🔗
Source: NVD

🛑 Raisecom Management Platform Exposed to Remote SQL Injection
Raisecom customers should prioritize containment and remediation, particularly for internet-accessible installations. Restrict access to the vulnerable application while awaiting or deploying a fix because exploitation details are already public.
CVE-2026-19764 is a SQL injection vulnerability in Raisecom Communication Command and Dispatch Management Platform up to version 7.6.5. Manipulating the sip argument in /app/users/getpwd.php can trigger the issue remotely. It is rated HIGH with CVSS 7.3, and a public exploit is available; the vendor reportedly did not respond to the disclosure.
🔗 Read more 🔗
Source: NVD

📂 DTStack Taier Chunk Check Endpoint Allows Path Traversal
Taier 1.4.0 deployments should be patched or isolated promptly, especially when the affected endpoint is reachable by untrusted users. Public exploit availability makes exposure worth addressing quickly.
CVE-2026-19762 affects DTStack Taier 1.4.0 and involves the Paths.ge function in FileChunkController.java within the Chunk-Check Endpoint. Manipulating the Name argument can cause path traversal and the attack can be launched remotely. The flaw is rated HIGH with CVSS 7.3, and a public exploit is available.
🔗 Read more 🔗
Source: NVD

📁 Dromara lamp-cloud Chunk Endpoint Hit by Path Traversal
Teams running lamp-cloud should reduce exposure of the affected endpoint and prioritize a fixed release when available. Because exploit details are public, exposed installations deserve immediate review.
CVE-2026-19758 is a path traversal vulnerability in dromara lamp-cloud up to version 5.10.0. The issue affects FileChunkController.java in the chunk-check endpoint and can be triggered remotely by manipulating the Name argument. It is rated HIGH with CVSS 7.3, and a public exploit exists; the project reportedly had not responded to the issue report.
🔗 Read more 🔗
Source: NVD

📤 Dromara lamp-cloud File Upload Controller Exposes Path Traversal
Administrators of lamp-cloud deployments should prioritize mitigation around file-upload functionality and install a fix when available. Public exploit code means externally exposed systems should be assessed without delay.
CVE-2026-19757 affects Dromara lamp-cloud up to version 5.10.0 and is located in FileAnyoneController.java within the File-Upload Controller. Manipulation of the bucket/bizType arguments can result in path traversal and can be initiated remotely. The vulnerability is rated HIGH with CVSS 7.3, and the exploit is public; the project reportedly had not responded to the disclosure.
🔗 Read more 🔗
Source: NVD

🌐 MCP RDF Explorer Server Exposed to Remote SSRF
Anyone deploying mcp-rdf-explorer 1.0.0 should restrict the MCP server from untrusted access and prioritize upgrading or applying a fix. Public exploit availability makes exposed instances a near-term concern.
CVE-2026-19753 is a server-side request forgery vulnerability in Model Context Protocol mcp-rdf-explorer 1.0.0. The flaw affects the explore_url function in src/mcp-rdf-explorer/server.py, where manipulation of the url argument can trigger SSRF remotely. It is rated HIGH with CVSS 7.3, and a public exploit is available; the vendor reportedly did not respond to the disclosure.
🔗 Read more 🔗
Source: NVD