Tag
Insufficient Entropy Vulnerability in Synology DiskStation Manager Login Logic
1 TTP 6 CVEsSynology DiskStation Manager (DSM) contains an insufficient entropy vulnerability in its login logic that allows remote, unauthenticated attackers to perform arbitrary file read/write operations and trigger a denial-of-service condition.
OS Command Injection in D-Link Virtual Volume Handler
3 rules 3 TTPs 1 CVED-Link DNS-340L and DNS-345 network storage devices are susceptible to remote OS command injection via the /cgi-bin/virtual_vol.cgi component, enabling unauthenticated remote code execution.
Unauthenticated Remote Code Execution in D-Link NAS Devices
1 rule 1 TTP 1 CVEMultiple D-Link NAS devices are vulnerable to unauthenticated OS command injection via the account_mgr.cgi script, allowing remote attackers to execute arbitrary commands with root privileges.
CVE-2026-16327: D-Link DNS-320 Unrestricted File Upload Vulnerability
4 rules 4 TTPs 2 IOCsA high-severity unrestricted file upload vulnerability (CVE-2026-16327) in D-Link DNS-320 firmware version 1.0.2 allows remote attackers to upload arbitrary files, potentially leading to remote code execution and full device compromise, with exploit code publicly disclosed.
EFM ipTIME NAS1dual Stack-Based Buffer Overflow Vulnerability
2 rules 1 TTP 1 CVEA stack-based buffer overflow vulnerability exists in EFM ipTIME NAS1dual 1.5.24, affecting the get_csrf_whites function in /cgi/advanced/misc_main.cgi, exploitable remotely, and leading to potential arbitrary code execution.