0.0

CVE-2025-60694 -

A stack-based buffer overflow exists in the validate_static_route function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function improperly concatenates user-supplied CGI parameters (route_ipaddr_0~3, route_netmask_0~3, route_gateway_0~3) into fixed-si…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 5 p.m.

0.0

CVE-2025-60689 -

An unauthenticated command injection vulnerability exists in the Start_EPI function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The vulnerability occurs because user-supplied CGI parameters (wl_ant, wl_ssid, wl_rate, ttcp_num, ttcp_ip, ttcp_size) are conc…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 3:57 p.m.

0.0

CVE-2025-60693 -

A stack-based buffer overflow exists in the get_merge_mac function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function concatenates up to six user-supplied CGI parameters matching <parameter>_0~5 into a fixed-size buffer (a2) without proper bounds ch…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 5:50 p.m.

0.0

CVE-2025-60698 -

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_432F60` function in `prog.cgi` stores user-supplied `SetSysLogSettings/IPAddress` values in NVRAM via `nvram_safe_set("SysLogRemote_IPAddress", ...)`. T…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 6:02 p.m.

0.0

CVE-2025-60697 -

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_4438A4` function in `prog.cgi` stores user-supplied DDNS parameters (`ServerAddress` and `Hostname`) in NVRAM via `nvram_safe_set`. These values are lat…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 6:01 p.m.

6.8

CVSS3.1

CVE-2025-55810 -

A vulnerability was found in Alaga Home Security WiFi Camera 3K (model S-CW2503C-H) with hardware version V03 and firmware version 1.4.2, which allows physical attackers to execute commands as root via script file with a specific name on a SD card.

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 6:15 p.m.

6.5

CVSS3.1

CVE-2025-47222 -

Keyfactor SignServer before 7.3.1 has Incorrect Access Control, issue 3 of 3.

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 5:16 p.m.

0.0

CVE-2025-52186 -

Lichess lila before commit 11b4c0fb00f0ffd823246f839627005459c8f05c (2025-06-02) contains a Server-Side Request Forgery (SSRF) vulnerability in the game export API. The players parameter is passed directly to an internal HTTP client without validation, allowing remote attackers to force the server …

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 3:23 p.m.

0.0

CVE-2025-60685 -

A stack buffer overflow exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary (sub_401EE0 function). The binary reads the /proc/stat file using fgets() into a local buffer and subsequently parses the line using sscanf() into a single-byte variable with the %s…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 3:35 p.m.

0.0

CVE-2025-60683 -

A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the sysconf binary, specifically in the sub_40BFA4 function that handles network interface reinitialization from '/var/system/linux_vlan_reinit'. Input is only partially validated by checkin…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 3:37 p.m.
Total resulsts: 318415
Page 30 of 31,842
Β« previous page Β» next page
Filters