PoC Archive PoC Archive

tag

Embedded

  • CVE-2025-29384 network CRITICAL 9.8

    Tenda AC9 `AdvSetMacMtuWan` Stack-Based Buffer Overflow (CVE-2025-29384)

    CVE-2025-29384 is a critical stack-based buffer overflow in the Tenda AC9 router's web management interface, specifically in the handling of the wanMTU POST parameter sent to the /goform/AdvSetMacMtuWan endpoint. The root cause is a lack of bounds checking…

    Unpatched 2026-07-06
  • CVE-2026-40003 hardware HIGH

    ZXIC/Sanechips ZX297520V3 BootROM Arbitrary Memory Write via USB Download Mode (CVE-2026-40003)

    The ZX297520V3 BootROM falls back to a USB download mode when it cannot load or verify a valid image from flash, entering a handshake loop that accepts a stage-1 image over USB for device recovery. The BootROM's image-load command does not validate the…

    Unverified 2026-07-05
  • CVE-2026-11499 network HIGH

    Tenda HG7/HG9/HG10 Router Stack-Based Buffer Overflow — CVE-2026-11499

    CVE-2026-11499 is a stack-based buffer overflow (CWE-121) in the web-management formDOMAINBLK handler of Tenda HG7/HG9/HG10 router firmware. The vulnerable code path copies the attacker-supplied blkDomain form parameter into a fixed-size stack buffer without…

    Unverified 2026-07-05
  • CVE-2026-56111 hardware HIGH 8.3

    Marlin Firmware M421 G-code Handler Out-of-Bounds Write — CVE-2026-56111

    Marlin's M421 G-code handler, used to set Mesh Bed Leveling (MBL) grid points, validates only that the supplied I/J grid indices are non-negative and never checks the upper bound against the actual mesh grid size. The underlying setz() function then writes…

    Patched 2026-07-05
  • CVE-2026-8836 network CRITICAL 9.8

    lwIP SNMPv3 USM Stack-Based Buffer Overflow (CVE-2026-8836)

    lwIP's SNMPv3 User-based Security Model (USM) handler contains a stack-based buffer overflow in snmpparseinboundframe(). A commented-out bounds check combined with an incorrect buffer-size parameter passed to snmpasn1decraw() allows an oversized…

    Patched 2026-07-05
  • CVE-2026-12485 network CRITICAL 10

    GeoVision GV-I/O Box 4E DVRSearch Unauthenticated Stack Buffer Overflow RCE (CVE-2026-12485)

    CVE-2026-12485 is a CVSS 10.0 unauthenticated stack-based buffer overflow in the GeoVision GV-I/O Box 4E, a Linux-based smart I/O device used in physical security and building automation. The DVRSearch service listens on UDP port 10001 and handles CMDIPSET…

    Patched 2026-06-30