tag
Router
Critical
D-Link DIR-820L `get_set.ccp` LAN Configuration OS Command Injection (CVE-2022-26258)
CVE-2022-26258·
D-Link DIR-820L wireless router, all hardware revisions
unpatched
Critical
XSpeeder SXZOS Pre-Auth eval() Remote Code Execution (CVE-2025-54322)
CVE-2025-54322·
XSpeeder SXZOS firmware (SD-WAN devices, routers, edge networking equipment)
unpatched
Critical
Tenda AC9 `AdvSetMacMtuWan` Stack-Based Buffer Overflow (CVE-2025-29384)
CVE-2025-29384·
Tenda AC9 dual-band wireless router, web management interface (/goform/AdvSetMacMtuWan endpoint)
unpatched
Critical
D-Link AX1500 SetDeviceSettings `DeviceName` OS Command Injection (CVE-2025-60854)
CVE-2025-60854·
D-Link AX1500 router firmware (HNAP/DHMAPI web management SOAP interface)
patched
High
Zyxel VMG3625-T50B Authenticated Command Injection to Root SSH Access (CVE-2026-1459)
CVE-2026-1459·
Zyxel VMG3625-T50B (and similar) router firmware
unpatched
High
ZTE ZXHN H298A / H108N Router Unauthenticated Credential Disclosure (CVE-2026-34474)
CVE-2026-34474·
ZTE ZXHN H298A (hardware 1.1) and ZXHN H108N (hardware 2.6) home routers
unpatched
Critical
ZTE ZXHN H188A Unauthenticated Wizard Handler Credential Disclosure / Auth Bypass (CVE-2026-34472)
CVE-2026-34472·
ZTE ZXHN H188A V6 home router firmware
unpatched
High
ZTE Router Unauthenticated Oversized-POST Denial of Service (CVE-2026-34473)
CVE-2026-34473·
ZTE H-series routers (17+ models, reported as affecting 140K+ devices)
unpatched
Critical
TP-Link DHCP Option 66 Unauthenticated RCE — CVE-2026-11834
CVE-2026-11834·
TP-Link router firmware (libcmm.so DHCP client), tested on Archer C20 V6
unpatched
High
Tenda HG7/HG9/HG10 Router Stack-Based Buffer Overflow — CVE-2026-11499
CVE-2026-11499·
Tenda HG7 / HG9 / HG10 routers (firmware family HG7_HG9_HG10re_300001138_en_xpon and similar)
unpatched
High
MR9600 Router Bluetooth/JNAP Management Interface RCE Injection (CVE-2026-6992)
CVE-2026-6992·
MR9600 router (Bluetooth-capable administrative interface)
unpatched
Critical
MeiG Smart FORGE_SLT711 GoAhead Unauthenticated OS Command Injection (CVE-2026-36356)
CVE-2026-36356·
MeiG Smart FORGE_SLT711 4G LTE CPE (GoAhead web server)
unpatched