Tag
Multiple Vulnerabilities in Botslab G980H Dashcams
2 TTPsBotslab G980H dash cameras are impacted by 14 firmware vulnerabilities allowing unauthenticated adjacent network attackers to bypass authentication, hijack sessions, and gain full control over device functionality.
Multiple Vulnerabilities in Siemens Reyrolle 7SR5 Firmware
1 CVESiemens Reyrolle 7SR5 devices running firmware versions earlier than V2.70 are impacted by multiple vulnerabilities within the embedded Mongoose Web Server, potentially leading to denial of service, information disclosure, or authentication bypass.
Remote Code Execution in Dell iDRAC7 and iDRAC8
1 rule 3 TTPs 1 CVECVE-2018-1207 allows unauthenticated attackers to achieve root-level remote code execution on Dell iDRAC7 and iDRAC8 firmware versions 2.52.52.52 and below via dynamic linker injection.
Remote Command Injection Vulnerability in Tenda CP3
2 TTPs 1 CVEAn unauthenticated remote command injection vulnerability in Tenda CP3 firmware version 27.5.57.101 allows attackers to execute arbitrary system commands via the AlarmVoiceURL argument.
Improper RSA Signature Validation in Phison PS3111-S11 Controller Firmware
2 TTPs 1 CVEThe Phison PS3111-S11 controller firmware is vulnerable to arbitrary firmware modification due to RSA signature validation against an embedded public modulus rather than immutable hardware-backed storage.
Authorization Bypass in GL.iNet WebDAV Service
1 rule 2 TTPs 1 CVEMultiple GL.iNet router models running firmware versions up to 4.8.x contain an authorization bypass vulnerability in the WebDAV service, allowing remote unauthenticated attackers to manipulate file operations.
Unauthenticated Remote Code Execution in Voltronic Power SNMP Web Pro
1 rule 2 TTPsVoltronic Power SNMP Web Pro version 1.1 contains an unauthenticated RCE vulnerability allowing attackers to upload and execute malicious CGI scripts as root by bypassing session validation.
ENDLESSDOORS Vulnerability Affecting Zbtlink Routers
1 TTPMultiple Zbtlink router models are susceptible to the ENDLESSDOORS root implant, which leverages the rctl remote control tool for unauthorized access and persistent phone-home capabilities.
CVE-2026-4769: Unauthenticated Remote Access in WAGO System I/O Field Series
2 TTPs 1 CVEA critical vulnerability, CVE-2026-4769, in certain WAGO System I/O Field series devices allows an unauthenticated remote attacker to gain full system compromise by accessing an undocumented internal diagnostic capability during the initial startup sequence.
Multiple High-Severity Vulnerabilities in EDK2 NetworkPkg IP Stack Implementation
4 TTPsMultiple high-severity vulnerabilities exist within the EDK2 NetworkPkg IP stack implementation, allowing an attacker, either from an adjacent network or remotely and anonymously, to achieve arbitrary code execution, disclose confidential information, and trigger a denial of service condition, impacting the low-level networking capabilities and security of systems utilizing this firmware component.