6.8

CVSS3.1

CVE-2025-60674 -

A stack buffer overflow vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin in the rc binary's USB storage handling module. The vulnerability occurs when the "Serial Number" field from a USB device is read via sscanf into a 64-byte stack buffer, while fgets reads up to 127 byt…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 7:04 p.m.

5.3

CVSS3.1

CVE-2025-47221 -

An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2. The properties ARCHIVETODISK_FILENAME-PATTERN, ARCHIVETODISK_PATH_BASE, ARCHIVETODISK_PATH_PATTERN can be set to any path, even ones that will point to files that already exist. This vulnerability gives a user with a…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Dec. 17, 2025, 8:15 p.m.

8.8

CVSS3.1

CVE-2025-60679 -

A stack buffer overflow vulnerability exists in the D-Link DIR-816A2 router firmware DIR-816A2_FWv1.10CNB05_R1B011D88210.img in the upload.cgi module, which handles firmware version information. The vulnerability occurs because /proc/version is read into a 512-byte buffer and then concatenated usin…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 5:57 p.m.

7.5

CVSS3.1

CVE-2025-60694 -

A stack-based buffer overflow exists in the validate_static_route function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function improperly concatenates user-supplied CGI parameters (route_ipaddr_0~3, route_netmask_0~3, route_gateway_0~3) into fixed-si…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 7:55 p.m.

5.9

CVSS3.1

CVE-2025-60695 -

A stack-based buffer overflow vulnerability exists in the mtk_dut binary of Linksys E7350 routers (Firmware 1.1.00.032). The function sub_4045A8 reads up to 256 bytes from /sys/class/net/%s/address into a local buffer and then copies it into caller-provided buffer a1 using strcpy without boundary c…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 7:55 p.m.

5.1

CVSS3.1

CVE-2025-60686 -

A local stack-based buffer overflow vulnerability exists in the infostat.cgi and cstecgi.cgi binaries of ToToLink routers (A720R V4.1.5cu.614_B20230630, LR1200GB V9.1.0u.6619_B20230130, and NR1800X V9.1.0u.6681_B20230703). Both programs parse the contents of /proc/net/arp using sscanf() with "%s" f…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 19, 2025, 5:41 p.m.

6.5

CVSS3.1

CVE-2025-60682 -

A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudupdate_check binary, specifically in the sub_402414 function that handles cloud update parameters. User-supplied 'magicid' and 'url' values are directly concatenated into shell comm…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 7:16 p.m.

7.3

CVSS3.1

CVE-2025-60697 -

A command injection vulnerability exists in the D-Link DIR-882 Router firmware DIR882A1_FW102B02 within the `prog.cgi` and `rc` binaries. The `sub_4438A4` function in `prog.cgi` stores user-supplied DDNS parameters (`ServerAddress` and `Hostname`) in NVRAM via `nvram_safe_set`. These values are lat…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 12:29 p.m.

6.5

CVSS3.1

CVE-2025-60693 -

A stack-based buffer overflow exists in the get_merge_mac function of the httpd binary on Linksys E1200 v2 routers (Firmware E1200_v2.0.11.001_us.tar.gz). The function concatenates up to six user-supplied CGI parameters matching <parameter>_0~5 into a fixed-size buffer (a2) without proper bounds ch…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 17, 2025, 7:55 p.m.

6.5

CVSS3.1

CVE-2025-60684 -

A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (sub_42F32C function). The web interface reads the "lang" parameter and constructs Help URL strings using sprintf() into …

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 24, 2025, 3:33 p.m.
Total resulsts: 349182
Page 3029 of 34,919
Β« previous page Β» next page
Filters