Skip to content
Threat Feed

Tag

Hardware

9 briefs RSS
critical advisory

Critical OS Command Injection in DrayTek VigorSwitch

Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability (CVE-2026-71921) in the setget.cgi interface that allows unauthenticated remote attackers to execute arbitrary commands as root.

VigorSwitch G2540xs +10 vulnerability remote-code-execution network-infrastructure cve network-security network hardware
1r 3t 1c
critical advisory

Critical RCE Vulnerability in IBM Power Systems Firmware ASMI

IBM Power Systems Firmware contains a stack-based buffer overflow in the ASMI web interface, allowing an unauthenticated attacker to achieve arbitrary code execution on the Flexible Service Processor.

Power Systems Firmware vulnerability remote-code-execution firmware hardware
2t 1c
critical threat

Unauthenticated Remote Code Execution in D-Link NAS Devices

Multiple D-Link NAS devices are vulnerable to unauthenticated OS command injection via the account_mgr.cgi script, allowing remote attackers to execute arbitrary commands with root privileges.

exploited DNS-320 +3 remote-code-execution nas hardware vulnerability
1r 1t 1c
medium advisory

Information Disclosure Vulnerability in AMD Zen Processors

An information disclosure vulnerability in AMD Zen processors allows an authorized local attacker to access sensitive information.

Zen vulnerability hardware information-disclosure
1t
medium advisory

Out-of-bounds Vulnerability in NXP i.MX 8 Image Signal Processor Driver

A potential out-of-bounds memory vulnerability in the NXP i.MX 8 Image Signal Processor (ISI) driver could lead to system instability or memory corruption if triggered by an attacker with driver-level access.

i.MX 8 ISI vulnerability kernel hardware informational
1c
high advisory

Multiple Vulnerabilities in Cisco Integrated Management Controller

Multiple vulnerabilities in the Cisco Integrated Management Controller allow remote, authenticated attackers to perform Cross-Site Scripting or execute arbitrary code with root privileges.

Integrated Management Controller vulnerability cisco hardware watchlist_match
2t
high advisory

MeiG Smart FORGE_SLT711 OS Command Injection Vulnerability

A command injection vulnerability exists in MeiG Smart FORGE_SLT711, as demonstrated by a public exploit, posing a high risk to unpatched systems.

FORGE_SLT711 command-injection hardware
2r 1t
medium advisory

D-Link DSL2600U 'rom-0' Admin Password Disclosure Vulnerability

A hardware exploit has been published on Exploit-DB for D-Link DSL2600U, detailing a 'rom-0' Admin Password Disclosure vulnerability that allows unauthorized access to the device's administration interface.

DSL2600U hardware password-disclosure d-link
2r
critical advisory

Linksys E1200 Authenticated Stack Buffer Overflow

A stack buffer overflow vulnerability in Linksys E1200 firmware version 2.0.04 and earlier allows an authenticated attacker to achieve remote code execution by sending a crafted HTTP POST request to the apply.cgi endpoint.

E1200 Firmware buffer-overflow rce hardware
2r 1t 1c