5.1
CVE-2025-53519 - Advantech iView Cross-site Scripting
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosurβ¦
5.1
CVE-2025-53397 - Advantech iView Cross-site Scripting
A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other mβ¦
8.7
CVE-2025-7419 - Tenda O3V2 httpd setRateTest fromSpeedTestSet stack-based overflow
A vulnerability was found in Tenda O3V2 1.0.0.12(3880). It has been classified as critical. This affects the function fromSpeedTestSet of the file /goform/setRateTest of the component httpd. The manipulation of the argument destIP leads to stack-based buffer overflow. It is possible to initiate theβ¦
7.2
CVE-2025-1727 - End-of-Train and Head-of-Train Remote Linking Protocol Weak Authentication
The protocol used for remote linking over RF for End-of-Train and Head-of-Train (also known as a FRED) relies on a BCH checksum for packet creation. It is possible to create these EoT and HoT packets with a software defined radio and issue brake control commands to the EoT device, disrupting opβ¦
8.7
CVE-2025-7418 - Tenda O3V2 httpd setPing fromPingResultGet stack-based overflow
A vulnerability was found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this issue is the function fromPingResultGet of the file /goform/setPing of the component httpd. The manipulation of the argument destIP leads to stack-based buffer overflow. The attack may be launched reβ¦
4.6
CVE-2025-31267 - Authentication State Mismanagement Allows Physical Access to Sensitive User Information on AppΒ Storβ¦
An authentication issue was addressed with improved state management. This issue is fixed in App Store Connect 3.0. An attacker with physical access to an unlocked device may be able to view sensitive user information.
8.7
CVE-2025-7417 - Tenda O3V2 httpd setPingInfo fromNetToolGet stack-based overflow
A vulnerability has been found in Tenda O3V2 1.0.0.12(3880) and classified as critical. Affected by this vulnerability is the function fromNetToolGet of the file /goform/setPingInfo of the component httpd. The manipulation of the argument ip leads to stack-based buffer overflow. The attack can be lβ¦
8.7
CVE-2025-7416 - Tenda O3V2 httpd setSysTimeInfo fromSysToolTime stack-based overflow
A vulnerability, which was classified as critical, was found in Tenda O3V2 1.0.0.12(3880). Affected is the function fromSysToolTime of the file /goform/setSysTimeInfo of the component httpd. The manipulation of the argument Time leads to stack-based buffer overflow. It is possible to launch the attβ¦
4.1
CVE-2025-53637 - Meshtastic allows Command Injection in GitHub Action
Meshtastic is an open source mesh networking solution. The main_matrix.yml GitHub Action is triggered by the pull_request_target event, which has extensive permissions, and can be initiated by an attacker who forked the repository and created a pull request. In the shell code execution part, user-cβ¦
4.3
CVE-2025-24798 - Meshtastic crashes via an unimplemented routing module reply
Meshtastic is an open source mesh networking solution. From 1.2.1 until 2.6.2, a packet sent to the routing module that contains want_response==true causes a crash. This can lead to a degradation of service for nodes within range of a malicious sender, or via MQTT if downlink is enabled. This vulneβ¦