Skip to content
Threat Feed

Tag

Firmware

21 briefs RSS
high advisory

Path Traversal Vulnerability in Zyxel Network Appliance CLI

An authenticated path traversal vulnerability in Zyxel ATP and USG series firmware allows administrators to execute arbitrary configuration files, potentially leading to command execution.

ATP series +3 path-traversal network-security firmware
1t 1c
critical advisory

Unauthenticated Remote Access to Phoenix Contact CHARX SEC MQTT Broker

A critical vulnerability (CVE-2026-44090) in Phoenix Contact CHARX SEC controllers allows unauthenticated remote attackers to gain full device control by bypassing authentication on the MQTT broker.

CHARX SEC-3150 +7 industrial-control-systems mqtt cve-2026-44091 ics cve injection authentication-bypass cve-2026-44100 +14
2r 5t 12c
critical threat

DD-WRT Stack-Based Buffer Overflow Vulnerability (CVE-2021-27137)

CVE-2021-27137 is a stack-based buffer overflow vulnerability in DD-WRT's UPnP component that allows an unauthenticated attacker to trigger remote code execution on affected router devices.

exploited DD-WRT +2 vulnerability-exploitation firmware router rce buffer-overflow
1t 4c
high advisory

Tenda AC10 Buffer Overflow Vulnerability (CVE-2026-16248)

A stack-based buffer overflow vulnerability (CVE-2026-16248) has been identified in Tenda AC10 firmware version 16.03.10.09_multi_TDE01, residing in the fromAdvSetLanip function of the /goform/AdvSetLanip file within the httpd/netctrl component, which can be remotely exploited by manipulating the GetValue/SetValue argument, with a public exploit now available.

AC10 16.03.10.09_multi_TDE01 buffer-overflow rce firmware router web-vulnerability cve
2t 1c 6i
high advisory

Shibby Tomato Router Firmware Out-of-Bounds Write Vulnerability (CVE-2026-16095)

A remote out-of-bounds write vulnerability, CVE-2026-16095, affects Shibby Tomato firmware version 1.28 RT-N5x MIPSR2 Build 124, where manipulating the `ct_tcp_timeout` argument in the `setup_conntrack` function of `/sbin/rc` can lead to memory corruption, potentially allowing arbitrary code execution or denial of service.

Tomato 1.28 RT-N5x MIPSR2 Build 124 vulnerability router firmware out-of-bounds-write CVE-2026-16095
3t 2c
high advisory

Public Exploit for Zephyr RTOS LwM2M Out-of-Bounds Read (CVE-2026-10672)

A public Proof of Concept (PoC) is available for CVE-2026-10672, an out-of-bounds read vulnerability in the LwM2M firmware update component of Zephyr RTOS versions 3.0.0 through 4.4.0, allowing an attacker to exfiltrate up to 13 bytes of sensitive data from adjacent memory via crafted CoAP requests, significantly elevating risk for unpatched IoT and embedded systems.

Zephyr RTOS +10 out-of-bounds-read data-exfiltration firmware rtos iot embedded
2t 1c 2i
critical advisory

Critical RCE Vulnerability in X-Rite MA-T6 Devices (CVE-2023-49900)

An unauthenticated remote attacker can achieve critical remote code execution in X-Rite MA-T6 devices running versions prior to v2.33 due to improper input sanitization in the `SetParameter` command, allowing for OS command injection via CVE-2023-49900.

MA-T6 rce command-injection os-command-injection firmware iot
2t 1c
critical advisory

Critical Remote Code Execution in Totolink NR1800X Routers (CVE-2026-15701)

A critical stack-based buffer overflow vulnerability, CVE-2026-15701 (CVSS 9.8), in Totolink NR1800X firmware version 9.1.0u.6279_B20210910 allows remote attackers to execute arbitrary code by manipulating the 'Host' argument in the 'Form_Logout' function, with a public exploit available.

NR1800X 9.1.0u.6279_B20210910 buffer-overflow remote-code-execution firmware router vulnerability
2t 1c 5i
high advisory

CVE-2026-15692: Tenda BE12 Pro Stack-Based Buffer Overflow Vulnerability

A stack-based buffer overflow vulnerability, identified as CVE-2026-15692, exists in Tenda BE12 Pro firmware version 16.03.66.23's `fromSafeUrlFilter` function, allowing remote attackers to achieve arbitrary code execution by manipulating the 'page' argument via a crafted HTTP request, with a public exploit available.

BE12 Pro vulnerability buffer-overflow rce firmware router network-device
1r 2t 1c 6i
high advisory

Tenda BE12 Pro Remote Code Execution Vulnerability (CVE-2026-15691)

A critical remote stack-based buffer overflow vulnerability (CVE-2026-15691) has been discovered in Tenda BE12 Pro firmware 16.03.66.23, affecting the `fromSafeClientFilter` function and allowing remote attackers to achieve arbitrary code execution by manipulating the `page` argument, with a public exploit available.

BE12 Pro 16.03.66.23 vulnerability remote-code-execution buffer-overflow firmware router network-device rce
2t 5c 8i
high advisory

Shibby Tomato Router Firmware Stack-Based Buffer Overflow (CVE-2026-15548)

A critical stack-based buffer overflow vulnerability (CVE-2026-15548) exists in Shibby Tomato router firmware versions up to 1.28.0000, specifically in the `sub_407220` function of the `/usr/sbin/httpd` component related to DNS List Rendering, allowing remote attackers to achieve high impact on confidentiality, integrity, and availability.

Tomato router firmware buffer-overflow rce CVE-2026-15548
2t 1c
high advisory

Shibby Tomato Firmware Vulnerability CVE-2026-15545 Leads to Remote Out-of-Bounds Write

A critical out-of-bounds write vulnerability (CVE-2026-15545) exists in Shibby Tomato firmware up to version 1.28.0000, specifically within the `main` function of the `www/apcupsd/tomatodata.cgi` file in the `apcupsd` component, which can be exploited remotely with a publicly available exploit, posing a significant risk to affected network devices.

Tomato vulnerability firmware router out-of-bounds-write CVE
2t 1c
high threat

Shibby Tomato Firmware Vulnerability CVE-2026-15544 Enables Remote Code Execution

A stack-based buffer overflow vulnerability, identified as CVE-2026-15544, exists in the `getupsvar` function within the `www/apcupsd/tomatodata.cgi` file of the `apcupsd` component in Shibby Tomato firmware versions up to and including 1.28.0000, allowing a remote attacker to achieve arbitrary code execution by manipulating the `Field` argument.

exploited Tomato buffer-overflow rce firmware router cve
2t 1c
critical advisory

Comfast Router CVE-2026-15511: Remote OS Command Injection

A critical remote OS command injection vulnerability, CVE-2026-15511, affects Comfast CF-WR631AX V3 WiFi routers, allowing unauthenticated remote attackers to execute arbitrary operating system commands by manipulating the 'filename' argument in the FastCGI Backend's file upload function, leading to full device compromise.

CF-WR631AX V3 vulnerability command-injection rce firmware router fastcgi
1r 2t 1c
high advisory

CVE-2026-11404: Cesanta Mongoose TLS Out-of-Bounds Read Leading to Denial of Service

Cesanta Mongoose before version 7.22 contains an out-of-bounds read vulnerability (CVE-2026-11404) in its built-in TLS server function, `mg_tls_server_recv_hello()`, allowing a remote, unauthenticated attacker to send a specially crafted TLS ClientHello message with an oversized session ID length, leading to a service crash and denial of service for HTTPS, MQTTS, or WSS services.

Mongoose denial-of-service vulnerability tls webserver firmware
1t 1c
high advisory

CVE-2026-29009 - U-Boot Buffer Overflow in nfs_readlink_reply()

A buffer overflow vulnerability exists in the nfs_readlink_reply() function of U-Boot versions up to 2026.04-rc3 when CONFIG_CMD_NFS is enabled, allowing a malicious or compromised NFS server to exploit it by sending multiple relative symlink targets, each approximately 1100 bytes long, to overflow the 2048-byte nfs_path_buff, corrupting adjacent BSS variables and potentially leading to memory corruption and control over the NFS client's state machine.

U-Boot <= 2026.04-rc3 buffer-overflow vulnerability firmware nfs u-boot
1c
critical advisory

CVE-2026-58457: Shenzhen Aitemi M300 Wi-Fi Repeater Unauthenticated OS Command Injection

An unauthenticated OS command injection vulnerability, CVE-2026-58457, exists in the Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02), allowing network-adjacent attackers to execute arbitrary shell commands and gain full root-level control by injecting unsanitized input into the `smacfilter_conf` handler's GET parameters within the `commuos` web backend.

M300 Wi-Fi Repeater +2 network command-injection vulnerability firmware iot
1r 2t 4i updated
high advisory

Insyde UEFI Firmware Vulnerability Allows Code Execution

A local attacker can exploit a vulnerability in Insyde UEFI Firmware to execute arbitrary program code, potentially leading to privilege escalation and system compromise.

UEFI Firmware uefi firmware code-execution privilege-escalation
2r 2t
high advisory

Multiple Vulnerabilities in Intel Firmware Allow Privilege Escalation and DoS

Multiple vulnerabilities in Intel Firmware allow a local attacker to escalate privileges, cause a denial-of-service condition, or disclose sensitive information.

Firmware intel privilege-escalation denial-of-service information-disclosure
2r 3t
high advisory

Intel IPU, UEFI Reference Firmware: Multiple Vulnerabilities

A local attacker can exploit multiple vulnerabilities in Intel Firmware to disclose confidential information or gain elevated privileges.

intel firmware vulnerability privilege-escalation credential-access
2r 2t
high advisory

Insyde UEFI Firmware Vulnerabilities Allow Local Privilege Escalation

Multiple vulnerabilities in Insyde UEFI Firmware allow a local attacker to execute arbitrary code with administrator privileges.

UEFI Firmware uefi privilege-escalation firmware
2r 1t