9.3

CVSS4.0

CVE-2026-6026 - Totolink A7100RU CGI cstecgi.cgi setPortalConfWeChat os command injection

A security flaw has been discovered in Totolink A7100RU 7.4cu.2313_b20191024. This vulnerability affects the function setPortalConfWeChat of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument enable results in os command injection. The attack can b…

📅 Published: April 10, 2026, 5:45 a.m. 🔄 Last Modified: April 10, 2026, 5:45 a.m.

9.3

CVSS4.0

CVE-2026-6025 - Totolink A7100RU CGI cstecgi.cgi setSyslogCfg os command injection

A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setSyslogCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Such manipulation of the argument enable leads to os command injection. It is possible to launch the attack remotely. The ex…

📅 Published: April 10, 2026, 5:30 a.m. 🔄 Last Modified: April 10, 2026, 5:30 a.m.

6.9

CVSS4.0

CVE-2026-6024 - Tenda i6 HTTP R7WebsSecurityHandlerfunction path traversal

A vulnerability was determined in Tenda i6 1.0.0.7(2204). Affected by this issue is the function R7WebsSecurityHandlerfunction of the component HTTP Handler. This manipulation causes path traversal. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be u…

📅 Published: April 10, 2026, 5:15 a.m. 🔄 Last Modified: April 10, 2026, 3:54 p.m.

8.2

CVSS4.0

CVE-2026-5477 - Prefix-substitution forgery via integer overflow in wolfCrypt CMAC

An integer overflow existed in the wolfCrypt CMAC implementation, that could be exploited to forge CMAC tags. The function wc_CmacUpdate used the guard `if (cmac->totalSz != 0)` to skip XOR-chaining on the first block (where digest is all-zeros and the XOR is a no-op). However, totalSz is word32 an…

📅 Published: April 10, 2026, 5:06 a.m. 🔄 Last Modified: April 10, 2026, 5:06 a.m.

8.7

CVSS4.0

CVE-2026-6016 - Tenda AC9 POST Request WizardHandle decodePwd stack-based overflow

A vulnerability was found in Tenda AC9 15.03.02.13. The affected element is the function decodePwd of the file /goform/WizardHandle of the component POST Request Handler. Performing a manipulation of the argument WANS results in stack-based buffer overflow. The attack can be initiated remotely. The…

📅 Published: April 10, 2026, 5 a.m. 🔄 Last Modified: April 10, 2026, 5 a.m.

8.7

CVSS4.0

CVE-2026-6015 - Tenda AC9 POST Request QuickIndex formQuickIndex stack-based overflow

A vulnerability has been found in Tenda AC9 15.03.02.13. Impacted is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. Such manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. It is possible to launch the attack remotely. …

📅 Published: April 10, 2026, 4:45 a.m. 🔄 Last Modified: April 10, 2026, 4:45 a.m.

8.7

CVSS4.0

CVE-2026-6014 - D-Link DIR-513 POST Request formAdvanceSetup buffer overflow

A flaw has been found in D-Link DIR-513 1.10. This issue affects the function formAdvanceSetup of the file /goform/formAdvanceSetup of the component POST Request Handler. This manipulation of the argument webpage causes buffer overflow. It is possible to initiate the attack remotely. The exploit ha…

📅 Published: April 10, 2026, 4:30 a.m. 🔄 Last Modified: April 10, 2026, 4:30 a.m.

6.8

CVSS4.0

CVE-2026-4482 - Insight Agent Private Key Information Disclosure via Inherited File Permissions

The installer certificate files in the …/bootstrap/common/ssl folder do not seem to have restricted permissions on Windows systems (users have read and execute access). For the client.key file in particular, this could potentially lead to exploits, as this exposes agent identity material to any loc…

📅 Published: April 10, 2026, 4:22 a.m. 🔄 Last Modified: April 10, 2026, 3:33 p.m.

8.7

CVSS4.0

CVE-2026-6013 - D-Link DIR-513 POST Request formSetRoute buffer overflow

A vulnerability was detected in D-Link DIR-513 1.10. This vulnerability affects the function formSetRoute of the file /goform/formSetRoute of the component POST Request Handler. The manipulation of the argument curTime results in buffer overflow. The attack may be performed from remote. The exploit…

📅 Published: April 10, 2026, 4:15 a.m. 🔄 Last Modified: April 10, 2026, 3:35 p.m.

8.7

CVSS4.0

CVE-2026-6012 - D-Link DIR-513 POST Request formSetPassword buffer overflow

A security vulnerability has been detected in D-Link DIR-513 1.10. This affects the function formSetPassword of the file /goform/formSetPassword of the component POST Request Handler. The manipulation of the argument curTime leads to buffer overflow. The attack is possible to be carried out remotel…

📅 Published: April 10, 2026, 4 a.m. 🔄 Last Modified: April 10, 2026, 3:54 p.m.
Total resulsts: 343921
Page 20 of 34,393
« previous page » next page
Filters