6.5

CVSS3.1

CVE-2025-60700 -

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `librcm.so` binaries. The `sub_4455BC` function in `prog.cgi` stores user-supplied `SetDMZSettings/IPAddress` values in NVRAM via `nvram_safe_set("dmz_ipaddr", ...)`. These val…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 5:16 p.m.

6.5

CVSS3.1

CVE-2025-60673 -

An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDMZSettings' functionality, where the 'IPAddress' parameter in prog.cgi is stored in NVRAM and later used by librcm.so to construct iptables commands e…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 5:16 p.m.

6.5

CVSS3.1

CVE-2025-60699 -

A buffer overflow vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `global.so` binary. The `getSaveConfig` function retrieves the `http_host` parameter from user input via `websGetVar` and copies it into a fixed-size stack buffer (`v13`) using `strcpy(…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 5:16 p.m.

6.5

CVSS3.1

CVE-2025-60672 -

An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetDynamicDNSSettings' functionality, where the 'ServerAddress' and 'Hostname' parameters in prog.cgi are stored in NVRAM and later used by rc to construc…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 5:16 p.m.

5.3

CVSS3.1

CVE-2025-47220 -

Keyfactor SignServer before 7.3.1 has Incorrect Access Control, issue 1 of 3.

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 6:15 p.m.

0.0

CVE-2025-60690 -

A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function concatenates up to four user-supplied CGI parameters matching <parameter>_0~3 into a fixed-size buffer (a2) without bounds check…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 4:17 p.m.

0.0

CVE-2025-60696 -

A stack-based buffer overflow vulnerability exists in the makeRequest.cgi binary of Linksys RE7000 routers (Firmware FW_v2.0.15_211230_1012). The arplookup function parses lines from /proc/net/arp using sscanf("%16s ... %18s ..."), storing results into buffers v6 (12 bytes) and v7 (20 bytes). Since…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 4:32 p.m.

0.0

CVE-2025-60692 -

A stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The functions get_mac_from_ip and get_ip_from_mac use sscanf with overly permissive "%100s" format specifiers to parse entries from /proc/net/arp …

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 4:31 p.m.

0.0

CVE-2025-60691 -

A stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The apply_cgi and block_cgi functions copy user-supplied input from the "url" CGI parameter into stack buffers (v36, v29) using sprintf without bounds checking. Because these…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 4:29 p.m.

0.0

CVE-2025-60695 -

A stack-based buffer overflow vulnerability exists in the mtk_dut binary of Linksys E7350 routers (Firmware 1.1.00.032). The function sub_4045A8 reads up to 256 bytes from /sys/class/net/%s/address into a local buffer and then copies it into caller-provided buffer a1 using strcpy without boundary c…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 4:51 p.m.
Total resulsts: 318415
Page 29 of 31,842
Β« previous page Β» next page
Filters