1.7

CVSS4.0

CVE-2025-62601 - FastDDS has heap buffer overflow in readString via Manipulated DATA Submessage when DDS Security is…

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes a heap buffer overfl…

📅 Published: Feb. 3, 2026, 7:16 p.m. 🔄 Last Modified: Feb. 18, 2026, 4:12 p.m.

8.2

CVSS4.0

CVE-2026-24441 - Tenda AC7 Transmits Admin Credentials Without HTTPS Protection

Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose account credentials in plaintext within HTTP responses, allowing an on-path attacker to obtain sensitive authentication material.

📅 Published: Feb. 3, 2026, 7:14 p.m. 🔄 Last Modified: April 18, 2026, 12:15 a.m.

5.1

CVSS4.0

CVE-2026-24434 - Tenda AC7 Web Interface Lacks CSRF Protections for Admin Actions

Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior does not implement CSRF protections for administrative functions in the web management interface. The interface does not enforce anti-CSRF tokens or robust origin validation, which can allow an attacker to induce a logged-in administrato…

📅 Published: Feb. 3, 2026, 7:13 p.m. 🔄 Last Modified: April 18, 2026, 6:45 p.m.

6.8

CVSS4.0

CVE-2026-24427 - Tenda AC7 Exposes Admin Credentials in Configuration Responses

Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior expose sensitive information in web management responses. Administrative credentials, including the router and/or admin panel password, are included in plaintext within configuration response bodies. In addition, responses lack appropria…

📅 Published: Feb. 3, 2026, 7:11 p.m. 🔄 Last Modified: April 18, 2026, 12:15 a.m.

8.6

CVSS3.1

CVE-2025-62600 - eprosima Fast DDS affected by Out-of-Memory in readBinaryPropertySeq via Manipulated DATA Submessag…

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to 2.6.11, 2.14.6, 3.2.4, 3.3.1, and 3.4.1, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes an Out-…

📅 Published: Feb. 3, 2026, 7:11 p.m. 🔄 Last Modified: April 20, 2026, 4:45 p.m.

5.1

CVSS4.0

CVE-2026-24426 - Tenda AC7 Reflected XSS via Web Interface Output Encoding

Shenzhen Tenda AC7 firmware version V03.03.03.01_cn and prior contain an improper output encoding vulnerability in the web management interface. User-supplied input is reflected in HTTP responses without adequate escaping, allowing injection of arbitrary HTML or JavaScript in a victim’s browser con…

📅 Published: Feb. 3, 2026, 7:09 p.m. 🔄 Last Modified: April 16, 2026, 5:30 p.m.

6.9

CVSS4.0

CVE-2026-1802 - Ziroom ZHOME A0101 zrMacClone.lua macAddrClone command injection

A security flaw has been discovered in Ziroom ZHOME A0101 1.0.1.0. This issue affects the function macAddrClone of the file luci\controller\api\zrMacClone.lua. The manipulation of the argument macType results in command injection. The attack may be launched remotely. The exploit has been released t…

📅 Published: Feb. 3, 2026, 7:02 p.m. 🔄 Last Modified: April 18, 2026, 8 p.m.

8.6

CVSS4.0

CVE-2025-62673 - Heap-based Buffer Overflow Vulnerability in TP-Link Archer AX53

Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tdpserver modules) allows adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containing a maliciously formed field.This issue affects Archer AX53 v1.0: th…

📅 Published: Feb. 3, 2026, 6:53 p.m. 🔄 Last Modified: March 16, 2026, 6:16 p.m.

7

CVSS4.0

CVE-2025-62501 - SSH Hostkey Misconfiguration Vulnerability in TP-Link Archer AX53

SSH Hostkey misconfiguration vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows attackers to obtain device credentials through a specially crafted man‑in‑the‑middle (MITM) attack. This could enable unauthorized access if captured credentials are reused.This issue affects Archer AX…

📅 Published: Feb. 3, 2026, 6:52 p.m. 🔄 Last Modified: March 16, 2026, 6:16 p.m.

7.3

CVSS4.0

CVE-2025-62405 - Heap-based Buffer Overflow Vulnerability in TP-Link Archer AX53

Heap-based Buffer Overflow vulnerability in TP-Link Archer AX53 v1.0 (tmpserver modules) allows authenticated adjacent attackers to cause a segmentation fault or potentially execute arbitrary code via a specially crafted network packet containing a field whose length exceeds the maximum expected va…

📅 Published: Feb. 3, 2026, 6:52 p.m. 🔄 Last Modified: March 16, 2026, 6:16 p.m.
Total resulsts: 347814
Page 1689 of 34,782
« previous page » next page
Filters