0.0

CVE-2025-60682 -

A command injection vulnerability exists in the ToToLink A720R Router firmware V4.1.5cu.614_B20230630 within the cloudupdate_check binary, specifically in the sub_402414 function that handles cloud update parameters. User-supplied 'magicid' and 'url' values are directly concatenated into shell comm…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 3:34 p.m.

0.0

CVE-2025-60688 -

A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (setDefResponse function). The binary reads the "IpAddress" parameter from a web request and copies it into a fixed-size …

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 3:44 p.m.

0.0

CVE-2025-60687 -

An unauthenticated command injection vulnerability exists in the ToToLink LR1200GB Router firmware V9.1.0u.6619_B20230130 within the cstecgi.cgi binary (sub_41EC68 function). The binary reads the "imei" parameter from a web request and verifies only that it is 15 characters long. The parameter is t…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 3:47 p.m.

0.0

CVE-2025-60686 -

A local stack-based buffer overflow vulnerability exists in the infostat.cgi and cstecgi.cgi binaries of ToToLink routers (A720R V4.1.5cu.614_B20230630, LR1200GB V9.1.0u.6619_B20230130, and NR1800X V9.1.0u.6681_B20230703). Both programs parse the contents of /proc/net/arp using sscanf() with "%s" f…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 3:53 p.m.

0.0

CVE-2025-60684 -

A stack buffer overflow vulnerability exists in the ToToLink LR1200GB (V9.1.0u.6619_B20230130) and NR1800X (V9.1.0u.6681_B20230703) Router firmware within the cstecgi.cgi binary (sub_42F32C function). The web interface reads the "lang" parameter and constructs Help URL strings using sprintf() into …

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 13, 2025, 3:42 p.m.

6.8

CVSS3.1

CVE-2025-60674 -

A stack buffer overflow vulnerability exists in the D-Link DIR-878A1 router firmware FW101B04.bin in the rc binary's USB storage handling module. The vulnerability occurs when the "Serial Number" field from a USB device is read via sscanf into a 64-byte stack buffer, while fgets reads up to 127 byt…

πŸ“… Published: Nov. 13, 2025, midnight πŸ”„ Last Modified: Nov. 14, 2025, 6:15 p.m.

5.1

CVSS4.0

CVE-2025-13076 - code-projects Responsive Hotel Site usersetting.php sql injection

A flaw has been found in code-projects Responsive Hotel Site 1.0. The affected element is an unknown function of the file /admin/usersetting.php. Executing manipulation of the argument usname can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be u…

πŸ“… Published: Nov. 12, 2025, 11:02 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 11:02 p.m.

5.1

CVSS4.0

CVE-2025-13075 - code-projects Responsive Hotel Site usersettingdel.php sql injection

A vulnerability was detected in code-projects Responsive Hotel Site 1.0. Impacted is an unknown function of the file /admin/usersettingdel.php. Performing manipulation of the argument eid results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be u…

πŸ“… Published: Nov. 12, 2025, 10:32 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 10:32 p.m.

1.2

CVSS4.0

CVE-2025-64707 - Frappe LMS revoking access did not show immediate effect as roles were cached

Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to version 2.41.0, when admins revoked a role from the user, the effect was not immediate because of caching. The issue has been fixed in version 2.41.0 by ensuring the cache is cleare…

πŸ“… Published: Nov. 12, 2025, 10:27 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 10:27 p.m.

1.3

CVSS4.0

CVE-2025-64705 - Frappe user was able to access the submission of other students

Frappe Learning is a learning system that helps users structure their content. Starting in version 2.0.0 and prior to version 2.41.0, users were able to access the submissions made by other students The issue has been fixed in version 2.41.0 by ensuring proper roles and redirecting if accessed via …

πŸ“… Published: Nov. 12, 2025, 10:25 p.m. πŸ”„ Last Modified: Nov. 12, 2025, 10:25 p.m.
Total resulsts: 318415
Page 31 of 31,842
Β« previous page Β» next page
Filters