Skip to content
Threat Feed

Tag

Network-Appliance

11 briefs RSS
high advisory

Remote Code Execution Vulnerability in Kaspersky Secure Mail Gateway

A critical remote code execution vulnerability, CVE-2023-41056, in Kaspersky Secure Mail Gateway allows unauthenticated attackers to execute arbitrary code on affected appliances.

Secure Mail Gateway vulnerability remote-code-execution network-appliance
2t 1c
critical advisory

Remote Command Injection Vulnerability in Tenda CP3

An unauthenticated remote command injection vulnerability in Tenda CP3 firmware version 27.5.57.101 allows attackers to execute arbitrary system commands via the AlarmVoiceURL argument.

CP3 remote-code-execution firmware-vulnerability iot network-appliance command-injection iot-vulnerability cve-2026-86152
2t 1c
critical advisory

Critical SSRF Vulnerability in SonicWall SMA1000 Appliances

SonicWall SMA1000 appliances are vulnerable to an unauthenticated server-side request forgery (SSRF) flaw, enabling remote attackers to access sensitive internal functionality and perform unauthorized operations.

SMA1000 Appliances vulnerability ssrf network-appliance
1t 2c
high advisory

Remote Out-of-Bounds Write Vulnerability in D-Link DSM-G600

A critical out-of-bounds write vulnerability in the D-Link DSM-G600 multipart handler allows remote attackers to compromise the device via the /load_file.cgi endpoint, with public exploit code currently available.

DSM-G600 vulnerability remote-code-execution network-appliance
1t 1c
high advisory

Authenticated Remote Code Execution in TP-Link Archer BE800

An authenticated remote code execution vulnerability (CVE-2026-16348) in the TP-Link Archer BE800 management interface allows attackers with administrator privileges to execute arbitrary commands via shell injection in the VPN key field.

Archer BE800 rce shell-injection router network-appliance
1t 1c
critical advisory

Critical Buffer Overflow in Wavlink Router Export Pingortrace CGI

A critical stack-based buffer overflow in Wavlink WN531P3 and WN535M1 devices allows remote code execution via crafted HTTP cookie data.

WN531P3 +1 cve-2026-74843 rce buffer-overflow network-appliance
1r 1t 1c
critical advisory

SonicWall SMA: Multiple Vulnerabilities

Multiple vulnerabilities in SonicWall SMA allow an unauthenticated, remote attacker to bypass security mechanisms and execute arbitrary operating system commands on the affected system, leading to full compromise of the appliance.

SonicWall SMA vulnerability rce sonicwall network-appliance
3t
high threat

SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability (CVE-2026-15409)

A critical server-side request forgery (SSRF) vulnerability, identified as CVE-2026-15409, exists in SonicWall SMA1000 Appliances, allowing a remote, unauthenticated attacker to force the appliance to make requests to arbitrary internal or external locations, potentially leading to information disclosure or access to restricted network services.

exploited PoC SMA1000 Appliances +6 ssrf vulnerability cisa-kev remote-code-execution network-appliance
2t 2c 6i updated
critical threat

Critical OS Command Injection in 9Router (CVE-2026-59800)

A critical OS command injection vulnerability (CVE-2026-59800) affects 9Router versions prior to 0.4.44, allowing unauthenticated remote attackers to execute arbitrary OS commands as root via a crafted POST request to the /api/tunnel/tailscale-install endpoint, leading to full system compromise with active exploitation observed.

exploited 9Router < 0.4.44 os-command-injection rce web-vulnerability network-appliance linux
1r 2t 1c
critical advisory

Multiple Critical Vulnerabilities in Fortinet Products Lead to RCE and Data Exposure

Multiple critical vulnerabilities (CVE-2025-67862, CVE-2026-25089, CVE-2026-49938) have been discovered across Fortinet products including FortiOS, FortiPortal, FortiProxy, and FortiSandbox, enabling unauthenticated attackers to achieve remote arbitrary code execution and compromise data confidentiality.

FortiOS +11 remote-code-execution data-exfiltration vulnerability fortinet network-appliance
2r 4t 3c 6i
critical advisory

Fortinet Appliance Authentication Bypass Vulnerability (CVE-2022-40684) Exploitation

Exploitation of CVE-2022-40684, a Fortinet appliance authentication bypass vulnerability, allows unauthorized REST API access to modify system configurations, potentially leading to complete system compromise.

FortiOS +2 cve-2022-40684 fortinet authentication-bypass network-appliance initial-access
2r 2t