Tag
Critical OS Command Injection in DrayTek VigorSwitch
1 rule 3 TTPs 1 CVEMultiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability (CVE-2026-71921) in the setget.cgi interface that allows unauthenticated remote attackers to execute arbitrary commands as root.
Critical RCE Vulnerability in IBM Power Systems Firmware ASMI
2 TTPs 1 CVEIBM Power Systems Firmware contains a stack-based buffer overflow in the ASMI web interface, allowing an unauthenticated attacker to achieve arbitrary code execution on the Flexible Service Processor.
Unauthenticated Remote Code Execution in D-Link NAS Devices
1 rule 1 TTP 1 CVEMultiple D-Link NAS devices are vulnerable to unauthenticated OS command injection via the account_mgr.cgi script, allowing remote attackers to execute arbitrary commands with root privileges.
Information Disclosure Vulnerability in AMD Zen Processors
1 TTPAn information disclosure vulnerability in AMD Zen processors allows an authorized local attacker to access sensitive information.
Out-of-bounds Vulnerability in NXP i.MX 8 Image Signal Processor Driver
1 CVEA potential out-of-bounds memory vulnerability in the NXP i.MX 8 Image Signal Processor (ISI) driver could lead to system instability or memory corruption if triggered by an attacker with driver-level access.
Multiple Vulnerabilities in Cisco Integrated Management Controller
2 TTPsMultiple vulnerabilities in the Cisco Integrated Management Controller allow remote, authenticated attackers to perform Cross-Site Scripting or execute arbitrary code with root privileges.
MeiG Smart FORGE_SLT711 OS Command Injection Vulnerability
2 rules 1 TTPA command injection vulnerability exists in MeiG Smart FORGE_SLT711, as demonstrated by a public exploit, posing a high risk to unpatched systems.
D-Link DSL2600U 'rom-0' Admin Password Disclosure Vulnerability
2 rulesA hardware exploit has been published on Exploit-DB for D-Link DSL2600U, detailing a 'rom-0' Admin Password Disclosure vulnerability that allows unauthorized access to the device's administration interface.
Linksys E1200 Authenticated Stack Buffer Overflow
2 rules 1 TTP 1 CVEA stack buffer overflow vulnerability in Linksys E1200 firmware version 2.0.04 and earlier allows an authenticated attacker to achieve remote code execution by sending a crafted HTTP POST request to the apply.cgi endpoint.