Skip to content
Threat Feed

Tag

Firmware-Vulnerability

10 briefs RSS
high advisory

Multiple Vulnerabilities in Botslab G980H Dashcams

Botslab G980H dash cameras are impacted by 14 firmware vulnerabilities allowing unauthenticated adjacent network attackers to bypass authentication, hijack sessions, and gain full control over device functionality.

G980H Dashcams +1 ics firmware-vulnerability transportation
2t
high advisory

Multiple Vulnerabilities in Siemens Reyrolle 7SR5 Firmware

Siemens Reyrolle 7SR5 devices running firmware versions earlier than V2.70 are impacted by multiple vulnerabilities within the embedded Mongoose Web Server, potentially leading to denial of service, information disclosure, or authentication bypass.

Reyrolle 7SR5 ics energy firmware-vulnerability
1c
critical advisory

Remote Code Execution in Dell iDRAC7 and iDRAC8

CVE-2018-1207 allows unauthenticated attackers to achieve root-level remote code execution on Dell iDRAC7 and iDRAC8 firmware versions 2.52.52.52 and below via dynamic linker injection.

iDRAC7 +1 cve-2018-1207 rce idrac remote-code-execution firmware-vulnerability
1r 3t 1c
critical advisory

Remote Command Injection Vulnerability in Tenda CP3

An unauthenticated remote command injection vulnerability in Tenda CP3 firmware version 27.5.57.101 allows attackers to execute arbitrary system commands via the AlarmVoiceURL argument.

CP3 remote-code-execution firmware-vulnerability iot network-appliance command-injection iot-vulnerability cve-2026-86152
2t 1c
high advisory

Improper RSA Signature Validation in Phison PS3111-S11 Controller Firmware

The Phison PS3111-S11 controller firmware is vulnerable to arbitrary firmware modification due to RSA signature validation against an embedded public modulus rather than immutable hardware-backed storage.

PS3111-S11 +1 hardware-security firmware-vulnerability persistence firmware-security privilege-escalation
2t 1c updated
high advisory

Authorization Bypass in GL.iNet WebDAV Service

Multiple GL.iNet router models running firmware versions up to 4.8.x contain an authorization bypass vulnerability in the WebDAV service, allowing remote unauthenticated attackers to manipulate file operations.

A1300 +16 cve-2026-19980 remote-code-execution network-security firmware-vulnerability vulnerability rce network-infrastructure
1r 2t 1c
high advisory

Unauthenticated Remote Code Execution in Voltronic Power SNMP Web Pro

Voltronic Power SNMP Web Pro version 1.1 contains an unauthenticated RCE vulnerability allowing attackers to upload and execute malicious CGI scripts as root by bypassing session validation.

SNMP Web Pro remote-code-execution cve-2026-44402 firmware-vulnerability
1r 2t
high advisory

ENDLESSDOORS Vulnerability Affecting Zbtlink Routers

Multiple Zbtlink router models are susceptible to the ENDLESSDOORS root implant, which leverages the rctl remote control tool for unauthorized access and persistent phone-home capabilities.

CPE2801 Firmware +19 firmware-vulnerability implant router network-security informational
1t
critical advisory

CVE-2026-4769: Unauthenticated Remote Access in WAGO System I/O Field Series

A critical vulnerability, CVE-2026-4769, in certain WAGO System I/O Field series devices allows an unauthenticated remote attacker to gain full system compromise by accessing an undocumented internal diagnostic capability during the initial startup sequence.

0765-110x/0100-0000 +7 ics ot critical-vulnerability unauthenticated-access remote-code-execution firmware-vulnerability
2t 1c
high advisory

Multiple High-Severity Vulnerabilities in EDK2 NetworkPkg IP Stack Implementation

Multiple high-severity vulnerabilities exist within the EDK2 NetworkPkg IP stack implementation, allowing an attacker, either from an adjacent network or remotely and anonymously, to achieve arbitrary code execution, disclose confidential information, and trigger a denial of service condition, impacting the low-level networking capabilities and security of systems utilizing this firmware component.

EDK2 NetworkPkg IP stack implementation firmware-vulnerability arbitrary-code-execution denial-of-service data-exfiltration edk2
4t