Tag: RouterSecurity

  • Vulnerability Watch No60

    AWX Archive Extraction Path Traversal • HCL Hive Third-Party Component Vulnerability • GIMP PCX Plugin Memory Corruption Bug • rConfig Authentication Bypass Creates Admin Accounts • NetworkManager WPA-Enterprise Validation Flaw…

  • Vulnerability Watch No54

    acmailer Authorization Flaw Enables Admin-Level Sub-Accounts • Atarim WordPress Plugin File Deletion Can Lead to RCE • TRENDnet Router Ping Interface Exposed to Command Injection • armeria-xds TLS Verification Flaw Enables MITM Attacks • TRENDnet TEW-823DRU Admin Endpoint Allows Command Injection…

  • Vulnerability Watch No50

    GL.iNet Routers Hit by Remote NAS Command Injection • Public Exploit Targets Edimax WAN Command Injection • Edimax Access Point Command Injection Exploit Goes Public • Critical ipTIME Authentication Bypass Has Public Exploit • Planet9 File Permissions Enable SYSTEM Privilege Escalation…

  • Vulnerability Watch No48

    WordPress Frontend Admin Flaw Enables Administrator Takeover • Royal Elementor Addons SSRF Exposes Internal Services • Podlove File Deletion Flaw Can Lead to Remote Code Execution • ProSolution WP Client Upload Bug Enables Unauthenticated RCE • Autopay WordPress Plugin Allows Unauthenticated Stored XSS…

  • Vulnerability Watch No45

    CrateDB Blob API Bypasses Table Privileges • Malicious Projects Can Trigger Code Execution in Cortex MCP • Recursive Jinja Rendering Enables Command Execution in compliance-trestle • Public Exploit Targets TOTOLINK A800R DHCP Handler • Public Exploit Exposes TOTOLINK A800R IPv6 Stack Overflow…

  • Vulnerability Watch No44

    Tenda G0 Port Mapping Flaw Enables Remote Buffer Overflow • Tenda G0 Static Route Bug Triggers Remote Stack Overflow • Tenda G0 Port Mirroring Endpoint Hit by Buffer Overflow • Tenda AC1206 Guest Wi-Fi Handler Exposed to Remote Overflow • Tenda AC1206 Device Naming Flaw Enables Remote Buffer Overflow…

  • Vulnerability Watch No36

    GStreamer ASF Demuxer Integer Flaws Trigger Out-of-Bounds Reads • GStreamer ADPCM Decoder Flaw Risks Memory Corruption and Code Execution • Uasoft Badaso File API Permission Flaw Has Public Exploit • ipTIME AX8004M Command Injection Has Public Exploit • Kingston FURY CTRL Driver Flaw Enables Improper Privilege Management…

  • Vulnerability Watch No35

    MingSoft MCMS SQL Injection Exposes Remote Attack Surface • node-sql-query SQL Injection Fixed in 0.1.29 • Aitemi M300 Command Injection Enables Remote Attacks • Tenda CH22 Command Injection Disclosed Publicly • Task Management System Hit by SQL Injection…

  • Vulnerability Watch No24

    Brace Expansion Bypass Enables Memory Exhaustion • Angular i18n Flaw Turns Translations into JavaScript • Angular Server Rendering Exposes High-Severity XSS • Angular Cache-Key Collision Can Return the Wrong Data • OpenEMR OAuth Flow Bypasses Multi-Factor Authentication…