8.8

CVSS3.1

CVE-2025-60690 -

A stack-based buffer overflow exists in the get_merge_ipaddr function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function concatenates up to four user-supplied CGI parameters matching <parameter>_0~3 into a fixed-size buffer (a2) without bounds check…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: March 17, 2026, 4:16 p.m.

6.5

CVSS3.1

CVE-2025-60688 -

A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (setDefResponse function). The binary reads the "IpAddress" parameter from a web request and copies it into a fixed-size …

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 5:33 p.m.

6.5

CVSS3.1

CVE-2025-60702 -

A command injection vulnerability exists in the TOTOLINK A950RG Router firmware V5.9c.4592_B20191022_ALL within the `system.so` binary. The `setDiagnosisCfg` function retrieves the `ipDoamin` parameter from user input via `websGetVar` and concatenates it directly into a `ping` system command execut…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 18, 2025, 1:49 a.m.

6.5

CVSS3.1

CVE-2025-60687 -

An unauthenticated command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619_B20230130 within the cstecgi.cgi binary (sub_41EC68 function). The binary reads the "imei" parameter from a web request and verifies only that it is 15 characters long. The parameter is t…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 5:38 p.m.

6.5

CVSS3.1

CVE-2025-60700 -

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `librcm.so` binaries. The `sub_4455BC` function in `prog.cgi` stores user-supplied `SetDMZSettings/IPAddress` values in NVRAM via `nvram_safe_set("dmz_ipaddr", ...)`. These val…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 12:28 p.m.

8.4

CVSS3.1

CVE-2025-60692 -

A stack-based buffer overflow vulnerability exists in the libshared.so library of Cisco Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The functions get_mac_from_ip and get_ip_from_mac use sscanf with overly permissive "%100s" format specifiers to parse entries from /proc/net/arp …

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 7:55 p.m.

6.5

CVSS3.1

CVE-2025-60676 -

An unauthenticated command injection vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin. The vulnerability occurs in the 'SetNetworkSettings' functionality of prog.cgi, where the 'IPAddress' and 'SubnetMask' parameters are directly concatenated into shell commands executed vi…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 5:58 p.m.

6.5

CVSS3.1

CVE-2025-52186 -

Lichess lila before commit 11b4c0fb00f0ffd823246f839627005459c8f05c (2025-06-02) contains a Server-Side Request Forgery (SSRF) vulnerability in the game export API. The players parameter is passed directly to an internal HTTP client without validation, allowing remote attackers to force the server …

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Jan. 9, 2026, 3:52 p.m.

6.5

CVSS3.1

CVE-2025-47222 -

A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any of the properties requiring a class path and the provided class is not expected to return different errors if the class exists in deployment or not. This returns information abou…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 8:15 p.m.

8.8

CVSS3.1

CVE-2025-60691 -

A stack-based buffer overflow exists in the httpd binary of Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The apply_cgi and block_cgi functions copy user-supplied input from the "url" CGI parameter into stack buffers (v36, v29) using sprintf without bounds checking. Because these…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 7:55 p.m.
Total resulsts: 349182
Page 3028 of 34,919
Β« previous page Β» next page
Filters