5.3

CVSS4.0

CVE-2025-9583 - Comfast CF-N1 webmgnt ping_config command injection

A vulnerability has been found in Comfast CF-N1 2.6.0. Affected by this vulnerability is the function ping_config of the file /usr/bin/webmgnt. The manipulation leads to command injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.

πŸ“… Published: Aug. 28, 2025, 8:02 p.m. πŸ”„ Last Modified: Oct. 2, 2025, 7:39 p.m.

7.5

CVSS3.1

CVE-2025-6203 - Vault unauthenticated denial of service through complex json payload

A malicious user may submit a specially-crafted complex payload that otherwise meets the default request size limit which results in excessive memory and CPU consumption of Vault. This may lead to a timeout in Vault’s auditing subroutine, potentially resulting in the Vault server to become unrespon…

πŸ“… Published: Aug. 28, 2025, 7:36 p.m. πŸ”„ Last Modified: Dec. 18, 2025, 5:55 p.m.

5.3

CVSS4.0

CVE-2025-9582 - Comfast CF-N1 webmgnt ntp_timezone command injection

A flaw has been found in Comfast CF-N1 2.6.0. Affected is the function ntp_timezone of the file /usr/bin/webmgnt. Executing manipulation of the argument timestr can lead to command injection. The attack may be launched remotely. The exploit has been published and may be used.

πŸ“… Published: Aug. 28, 2025, 7:32 p.m. πŸ”„ Last Modified: Sept. 11, 2025, 1:08 p.m.

5.3

CVSS4.0

CVE-2025-9581 - Comfast CF-N1 webmgnt multi_pppoe command injection

A vulnerability was detected in Comfast CF-N1 2.6.0. This impacts the function multi_pppoe of the file /usr/bin/webmgnt. Performing manipulation of the argument phy_interface results in command injection. The attack may be initiated remotely. The exploit is now public and may be used.

πŸ“… Published: Aug. 28, 2025, 7:02 p.m. πŸ”„ Last Modified: Sept. 11, 2025, 1:24 p.m.

5.3

CVSS4.0

CVE-2025-9580 - LB-LINK BL-X26 HTTP set_blacklist os command injection

A security vulnerability has been detected in LB-LINK BL-X26 1.2.8. This affects an unknown function of the file /goform/set_blacklist of the component HTTP Handler. Such manipulation of the argument mac leads to os command injection. The attack can be launched remotely. The exploit has been disclo…

πŸ“… Published: Aug. 28, 2025, 7:02 p.m. πŸ”„ Last Modified: Sept. 12, 2025, 4:18 p.m.

5.3

CVSS4.0

CVE-2025-9579 - LB-LINK BL-X26 HTTP set_hidessid_cfg os command injection

A weakness has been identified in LB-LINK BL-X26 1.2.8. The impacted element is an unknown function of the file /goform/set_hidessid_cfg of the component HTTP Handler. This manipulation of the argument enable causes os command injection. The attack can be initiated remotely. The exploit has been ma…

πŸ“… Published: Aug. 28, 2025, 6:32 p.m. πŸ”„ Last Modified: Sept. 11, 2025, 1:40 p.m.

2

CVSS4.0

CVE-2025-9577 - TOTOLINK X2000R Administrative shadow.sample default credentials

A security flaw has been discovered in TOTOLINK X2000R up to 2.0.0. The affected element is an unknown function of the file /etc/shadow.sample of the component Administrative Interface. The manipulation results in use of default credentials. Attacking locally is a requirement. Attacks of this natur…

πŸ“… Published: Aug. 28, 2025, 6:32 p.m. πŸ”„ Last Modified: Sept. 9, 2025, 7:13 p.m.

5.1

CVSS3.1

CVE-2025-31971 - AIML Solutions for HCL SX is susceptible to a URL validation vulnerability

AIML Solutions for HCL SX is vulnerable to a URL validation vulnerability.Β  The issue may allow attackers to launch a server-side request forgery (SSRF) attack enabling unauthorized network calls from the system, potentially exposing internal services or sensitive information.

πŸ“… Published: Aug. 28, 2025, 6:04 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

2

CVSS4.0

CVE-2025-9576 - seeedstudio ReSpeaker Administrative shadow default credentials

A vulnerability was identified in seeedstudio ReSpeaker LinkIt7688. Impacted is an unknown function of the file /etc/shadow of the component Administrative Interface. The manipulation leads to use of default credentials. An attack has to be approached locally. A high degree of complexity is needed …

πŸ“… Published: Aug. 28, 2025, 6:02 p.m. πŸ”„ Last Modified: Sept. 9, 2025, 7:13 p.m.

5.3

CVSS4.0

CVE-2025-9575 - Linksys RE6250/RE6300/RE6350/RE6500/RE7000/RE9000 upload.cgi cgiMain os command injection

A vulnerability was determined in Linksys RE6250, RE6300, RE6350, RE6500, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001. This issue affects the function cgiMain of the file /cgi-bin/upload.cgi. Executing manipulation of the argument filename can lead to os command inject…

πŸ“… Published: Aug. 28, 2025, 6:02 p.m. πŸ”„ Last Modified: Sept. 4, 2025, 6:32 p.m.
Total resulsts: 349182
Page 4097 of 34,919
Β« previous page Β» next page
Filters