tag
Iot
D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258)
D-Link DIR-820L firmware 1.05B03 contains an OS command injection (CWE-78) in the router's /getset.ccp LAN-configuration handler. The lanHostCfgDeviceName1.1.1.0 parameter (submitted from the "Device Name" field on the lan.asp LAN setup page) is filtered by…
Xiongmai XM530 IP Camera ONVIF Authentication Bypass (CVE-2025-65856)
CVE-2025-65856 is a critical authentication bypass in the ONVIF implementation shipped on Xiongmai XM530-based IP cameras. The device's deviceservice and mediaservice ONVIF SOAP endpoints accept and fully process requests such as GetDeviceInformation,…
ThingsBoard IoT Platform SSRF via SVG Image Upload (CVE-2025-34282)
ThingsBoard versions before 4.2.1 are vulnerable to Server-Side Request Forgery (CWE-918) through its Image Upload Gallery feature. A Tenant Admin can upload a crafted SVG file whose <image xlink:href="..."> (or <pattern>/<image>) element references an…
Tenda AC9 `AdvSetMacMtuWan` Stack-Based Buffer Overflow (CVE-2025-29384)
CVE-2025-29384 is a critical stack-based buffer overflow in the Tenda AC9 router's web management interface, specifically in the handling of the wanMTU POST parameter sent to the /goform/AdvSetMacMtuWan endpoint. The root cause is a lack of bounds checking…
D-Link AX1500 SetDeviceSettings `DeviceName` OS Command Injection (CVE-2025-60854)
The D-Link AX1500 web management interface exposes a SetDeviceSettings SOAP action (reached via the /DHMAPI/ HNAP-style endpoint) that lets a client update the router's DeviceName. The vulnerable firmware function (identified in the binary as…
Zyxel VMG3625-T50B Authenticated Command Injection to Root SSH Access (CVE-2026-1459)
The router's web management interface exposes a TR369Certificates CGI endpoint whose name parameter, used during a certificate "download" action, is passed unsanitized into a shell command executed as root. An authenticated administrator (or attacker with…
ZTE ZXHN H298A / H108N Router Unauthenticated Credential Disclosure (CVE-2026-34474)
CVE-2026-34474 is an unauthenticated information disclosure in the web management interface of ZTE ZXHN H298A and H108N router firmware. A crafted GET request to getpage.lua?pid=1000ÐCheat=1 returns HTML containing the live administrator password, WLAN…
ZTE ZXHN H188A Unauthenticated Wizard Handler Credential Disclosure / Auth Bypass (CVE-2026-34472)
CVE-2026-34472 is an authentication bypass in ZTE ZXHN H188A V6 routers caused by unauthenticated access to pre-login "wizard" handlers. Root-path routing trusts attacker-controlled type/tag parameters, and the QuickSetupEnable gate that should block this…
ZTE Router Unauthenticated Oversized-POST Denial of Service (CVE-2026-34473)
CVE-2026-34473 is an unauthenticated denial-of-service condition in ZTE H-series routers' web management interface, rooted in how the cgilua/post.lua pre-auth request-body parser handles oversized application/x-www-form-urlencoded POST bodies. Sending a…
Wyze Cam Pan v3 / TUTK SDK — tutk_packet_alloc Heap Overflow (CVE-2026-38698)
The tutkpacketalloc function inside the TUTK SDK's tutkavserver component, used by Wyze Cam Pan v3 and other TUTK-integrated IoT cameras, allocates a buffer for incoming AV packets based on an attacker-influenced size field without adequate bounds validation.…
TP-Link Tapo C260 Unauthenticated-to-Root RCE Chain — CVE-2026-0651
This PoC chains three vulnerabilities in the TP-Link Tapo C260 camera to go from unauthenticated (or guest-level) access to root command execution. First, a path traversal flaw in the HTTP GET handler allows arbitrary local file disclosure. Second, a…
TP-Link DHCP Option 66 Unauthenticated RCE — CVE-2026-11834
TP-Link router firmware processes DHCP Option 66 ("TFTP Server Name") from a lease it acquires on its WAN interface by concatenating the value unsanitized into a tftp shell command inside libcmm.so, which is ultimately passed to system() via utilexecSystem().…
TP-Link Archer C64 Web UI Rate-Limit Bypass via Residual Debug SSH Service (CVE-2026-8697)
The TP-Link Archer C64 exposes a residual debug SSH service (port 22) that does not grant a shell — it simply closes the connection once a password is entered — but validates the password against the same credential used by the router's web admin interface,…
Tenda HG7/HG9/HG10 Router Stack-Based Buffer Overflow — CVE-2026-11499
CVE-2026-11499 is a stack-based buffer overflow (CWE-121) in the web-management formDOMAINBLK handler of Tenda HG7/HG9/HG10 router firmware. The vulnerable code path copies the attacker-supplied blkDomain form parameter into a fixed-size stack buffer without…
Tasmota fetch_jpg() strcpy() Buffer Overflow in boundary[40] (CVE-2026-38426)
The fetchjpg() function's initial-connection handling (case 0) in Tasmota's scripter driver extracts the MJPEG multipart boundary string from the HTTP Content-Type response header and copies it into a fixed 40-byte boundary[40] field of the JPGTASK struct…
Tasmota fetch_jpg() Integer Wraparound to Heap Corruption (CVE-2026-38427)
When fetching subsequent MJPEG frames (case 2) in Tasmota's scripter driver, fetchjpg() reads the Content-Length header value via atoi() into a uint16t variable. Values above 65535 silently wrap around (e.g. 65537 becomes 1), causing the device to allocate a…
Tasmota fetch_jpg() Combined Buffer Overflow RCE Chain (CVE-2026-38422)
Tasmota's scripter driver (xdrv10scripter.ino) implements an MJPEG client via fetchjpg() that contains two compounding memory-corruption bugs: a strcpy() overflow of a fixed 40-byte boundary[] buffer when parsing the Content-Type boundary string…
OpenRemote — Expression Injection RCE in Rules Engine (CVE-2026-39842)
OpenRemote's Rules Engine evaluates user-supplied JavaScript rule expressions using the Java Nashorn scripting engine with no sandboxing, SecurityManager, or ClassFilter restrictions. While the API layer explicitly blocks non-superusers from creating Groovy…
MR9600 Router Bluetooth/JNAP Management Interface RCE Injection (CVE-2026-6992)
MR9600 routers with Bluetooth management capability expose a vulnerable JNAP request path that allows command injection via the Bluetooth PIN configuration flow, enabling an attacker to execute arbitrary commands on the router. The PoC reverses the original…
GeoVision GV-I/O Box 4E DVRSearch Unauthenticated Stack Buffer Overflow RCE (CVE-2026-12485)
CVE-2026-12485 is a CVSS 10.0 unauthenticated stack-based buffer overflow in the GeoVision GV-I/O Box 4E, a Linux-based smart I/O device used in physical security and building automation. The DVRSearch service listens on UDP port 10001 and handles CMDIPSET…