Tag
Unauthenticated Credential Disclosure in Vacron VIN-DS783E-E6 via Hidden Functionality (CVE-2026-18191)
2 TTPs 1 CVECVE-2026-18191 describes a critical Hidden Functionality vulnerability in Vacron VIN-DS783E-E6 devices that allows unauthenticated remote attackers to exploit a specific hidden function to obtain administrator credentials, leading to full device compromise.
CVE-2026-14169: Ads-tec DVG-IRF Series Vulnerability Allows Remote Admin Lockout
1 TTP 1 CVEA low-privileged remote attacker can exploit an incorrect behavior order vulnerability (CVE-2026-14169, CWE-696) in multiple ads-tec Industrial IT DVG-IRF series devices (versions prior to 2.3.0) by sending crafted input, leading to inconsistent account states and password overwrites, resulting in complete administrative unavailability of the device.
Intel Ethernet Products: Multiple Vulnerabilities
2 TTPsMultiple vulnerabilities exist in various Intel Ethernet products, which an attacker can exploit to trigger a denial-of-service condition and expose confidential information.
OPNsense: Multiple Vulnerabilities
4 TTPsAn attacker can exploit multiple vulnerabilities in OPNsense to bypass security controls, disclose information, perform Cross-Site Scripting (XSS) attacks, and execute Denial of Service (DoS) attacks.
Zyxel AX7501-B1 Firmware Command Injection (CVE-2026-6952)
1 TTP 1 CVEA post-authentication command injection vulnerability (CVE-2026-6952) in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5.17(ABPC.7.2)C0 allows an authenticated attacker with administrator privileges to execute arbitrary OS commands on the affected device.
CVE-2026-15692: Tenda BE12 Pro Stack-Based Buffer Overflow Vulnerability
1 rule 2 TTPs 1 CVE 6 IOCsA stack-based buffer overflow vulnerability, identified as CVE-2026-15692, exists in Tenda BE12 Pro firmware version 16.03.66.23's `fromSafeUrlFilter` function, allowing remote attackers to achieve arbitrary code execution by manipulating the 'page' argument via a crafted HTTP request, with a public exploit available.
Tenda BE12 Pro Remote Code Execution Vulnerability (CVE-2026-15691)
2 TTPs 5 CVEs 8 IOCsA critical remote stack-based buffer overflow vulnerability (CVE-2026-15691) has been discovered in Tenda BE12 Pro firmware 16.03.66.23, affecting the `fromSafeClientFilter` function and allowing remote attackers to achieve arbitrary code execution by manipulating the `page` argument, with a public exploit available.
Critical Buffer Overflow in Tenda CH22 Leads to Remote Code Execution (CVE-2026-15543)
1 TTP 1 CVEA critical buffer overflow vulnerability, CVE-2026-15543, exists in the Tenda CH22 1.0.0.1 firmware's `formCertListInfo` function, allowing unauthenticated remote attackers to achieve arbitrary code execution by manipulating the 'Name' argument, with a public exploit available.
LuCI DHCPv6 Lease Hostname Stored Cross-Site Scripting Vulnerability (CVE-2026-61876)
1 TTP 1 CVELuCI versions are vulnerable to CVE-2026-61876, a stored Cross-Site Scripting (XSS) flaw in their DHCPv6 lease hostname rendering logic, allowing an adjacent network attacker to inject malicious HTML markup that executes in an administrator's browser when viewing DHCP lease status pages.
Remote Buffer Overflow Vulnerability in TRENDnet TEW-821DAP Access Point
1 CVEA critical buffer overflow vulnerability (CVE-2026-15484) exists in the `sub_41EC14` function within the `/goform/tools_nslookup` component of the TRENDnet TEW-821DAP 1.12B01 wireless access point, which can be exploited remotely due to improper handling of the ssi element, potentially leading to arbitrary code execution on an End-of-Life device.
Remote Command Injection in Trendnet TEW-635BRM Routers (CVE-2026-15481)
1 TTP 1 CVEA critical remote command injection vulnerability (CVE-2026-15481) has been discovered in Trendnet TEW-635BRM routers up to version 1.00.03, allowing attackers to execute arbitrary commands by manipulating the 'ipoa_ipaddr' argument in the 'ipoa_test' function, with public exploits available for this End-of-Life product.
H3C NX15 Weak Password Recovery Vulnerability (CVE-2026-15479)
2 TTPs 1 CVE 5 IOCsA critical vulnerability, CVE-2026-15479, in H3C NX15 V100R017 allows remote attackers to perform weak password recovery by manipulating the 'newPass' argument in the '/api/login/modify' endpoint, leading to unauthorized administrator access.
Juniper Networks Releases Security Advisories for Multiple Vulnerabilities, Including Heap Buffer Overflow and Memory Leak
2 TTPs 1 CVEJuniper Networks has released security advisories to address multiple vulnerabilities across several products, including Juniper cRPD, CTPView, Network Director, Junos OS, Junos OS Evolved, Junos OS on MX Series with SPC3 and SRX Series, and Junos Space, with key vulnerabilities like a heap buffer overflow (CVE-2020-7450) and a memory leak (CVE-2026-33799) potentially leading to arbitrary code execution or denial of service.
CVE-2026-0284 PAN-OS: XML Injection Vulnerability in Large Scale VPN (LSVPN)
3 TTPsAn XML injection vulnerability (CVE-2026-0284) in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS software allows an unauthenticated attacker with network access to inject malicious XML content, potentially leading to information disclosure or corruption of internal LSVPN satellite data.
CVE-2026-0286 PAN-OS: Authenticated Command Injection in CLI
3 TTPsA command injection vulnerability, CVE-2026-0286, in the management plane of Palo Alto Networks PAN-OS software allows an authenticated administrator to execute arbitrary OS commands as root on PA-Series and VM-Series firewalls and Panorama (virtual and M-Series) devices, potentially leading to high system compromise.
CVE-2026-0285 PAN-OS: Server-Side Request Forgery Vulnerability in Management Web Interface
3 TTPsA server-side request forgery (SSRF) vulnerability, tracked as CVE-2026-0285, exists in the management web interface of Palo Alto Networks PAN-OS software, allowing an authenticated administrator with network access to make unauthorized requests from the firewall to internal services, potentially leading to information disclosure or further network compromise.
CVE-2026-0283: Authentication Bypass in Palo Alto Networks PAN-OS Large Scale VPN (LSVPN)
1 TTPAn authentication bypass vulnerability, CVE-2026-0283, in Palo Alto Networks PAN-OS software allows an unauthenticated attacker with network access to establish an unauthorized site-to-site VPN connection when LSVPN functionality with configured satellites is enabled, leading to potential access to internal network resources.
CVE-2026-0279 PAN-OS: Multiple Cross-Site Scripting (XSS) Vulnerabilities
2 TTPsPalo Alto Networks has disclosed multiple low-severity cross-site scripting (XSS) vulnerabilities, CVE-2026-0279, in PAN-OS software affecting the User-ID Authentication Portal, GlobalProtect gateway/portal features, and Clientless VPN, which could allow a malicious unauthenticated user to inject and execute JavaScript in a victim's browser.
CVE-2026-0281 PAN-OS: Information Disclosure Vulnerability in Management Web Interface
2 TTPsAn information disclosure vulnerability (CVE-2026-0281) in Palo Alto Networks PAN-OS software allows an unauthenticated attacker to obtain web session tokens via user interaction with a malicious link, potentially leading to unauthorized access to the management interface.
CVE-2026-0282 PAN-OS: Unauthenticated File Deletion Vulnerability
An unauthenticated attacker with network access to the management web interface of Palo Alto Networks PAN-OS software can exploit CVE-2026-0282, a file deletion vulnerability, to delete files from a temporary directory, impacting PA-Series and VM-Series firewalls, and Panorama appliances.
CVE-2026-14721: UTT HiPER 1250GW Remote Code Execution via Buffer Overflow
2 TTPs 1 CVEA critical stack-based buffer overflow vulnerability (CVE-2026-14721) in UTT HiPER 1250GW firmware versions up to 3.2.7-210907-180535 allows remote, unauthenticated attackers to achieve arbitrary code execution by manipulating the 'ssid' argument in the /goform/ConfigWirelessBase_5g web endpoint, with public exploit disclosure indicating active exploitation risk.
WatchGuard Firebox and Mobile VPN Client Vulnerabilities
2 TTPsWatchGuard has released security advisories to address critical vulnerabilities, including a race condition, use-after-free, and local privilege escalation, in its Fireware OS and Mobile VPN with SSL client for Windows, which could lead to remote code execution on appliances and local privilege escalation on client systems if not patched immediately.
FortiGate VPN SSL Settings Modified
1 rule 2 TTPsDetection of FortiGate VPN SSL settings modification, such as authentication rules, linked to observed exploitation campaigns (e.g., CVE-2024-535), which threat actors leverage for persistence and unauthorized access after initial compromise.
FortiGate - New VPN SSL Web Portal Added
1 rule 2 TTPsThis brief details a detection for the addition of a new VPN SSL Web Portal on FortiGate Firewalls, a configuration change that could be utilized by attackers for establishing persistence or initial access to external remote services, as indicated by observed modifications of VPN SSL settings.
Detection of FortiGate Firewall Address Object Addition
1 ruleThis brief details the detection of firewall address objects being added on Fortinet FortiGate devices, a configuration change that, while potentially legitimate, can also indicate post-compromise activity or unauthorized access, especially when tied to vulnerabilities like FG-IR-24-535, enabling threat actors to bypass security controls or facilitate command and control.
FortiGate - New Administrator Account Created
1 rule 1 TTPThis brief describes how to detect the creation of new administrator accounts on Fortinet FortiGate firewalls, a behavior often used by attackers for persistence (ATT&CK T1136.001) or to maintain unauthorized access after initial compromise.
Multiple Vulnerabilities in Squid Proxy (CVE-2026-47729, CVE-2026-50012)
3 TTPs 2 CVEsMultiple vulnerabilities, including CVE-2026-47729 and CVE-2026-50012, have been identified in Squid proxy versions prior to 7.6, allowing an attacker to compromise data confidentiality and cause other unspecified security issues.
UTT HiPER 1200GW Stack-Based Buffer Overflow Vulnerability (CVE-2026-10293)
2 rules 1 TTP 1 CVEA stack-based buffer overflow vulnerability (CVE-2026-10293) exists in UTT HiPER 1200GW up to version 2.5.3-170306 due to the strcpy function in /goform/formFireWall, allowing remote exploitation via manipulation of the Profile argument.
TRENDnet TEW-432BRP Stack-Based Buffer Overflow Vulnerability (CVE-2026-10123)
2 rules 1 TTP 1 CVEA stack-based buffer overflow vulnerability (CVE-2026-10123) exists in TRENDnet TEW-432BRP version 3.10B20 within the formSetDomainFilter function, allowing a remote attacker to execute arbitrary code by manipulating specific arguments in a request to /goform/formSetDomainFilter.
Hirschmann HiSecOS Vulnerability Allows Privilege Escalation
2 rules 1 TTPAn authenticated remote attacker can exploit a vulnerability in Hirschmann HiSecOS to escalate privileges, potentially gaining unauthorized access and control over the affected system.
CVE-2026-9456 - Totolink A8000RU Remote Command Injection
2 rules 1 TTP 1 CVETotolink A8000RU version 7.1cu.643_b20200521 is vulnerable to remote command injection via the setOpenVpnCfg function, allowing unauthenticated attackers to execute arbitrary commands on the device.
Totolink A8000RU Command Injection Vulnerability (CVE-2026-9408)
3 rules 1 TTP 1 CVETotolink A8000RU version 7.1cu.643_b20200521 is vulnerable to command injection via the setStaticDhcpRules function in the /cgi-bin/cstecgi.cgi file, allowing remote attackers to execute arbitrary OS commands by manipulating the 'enable' argument, and a public exploit is available.
Taiko AG1000-01A SMS Alert Gateway Hardcoded Credentials Vulnerability (CVE-2026-9139)
2 rules 1 TTP 1 CVETaiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability (CVE-2026-9139) in the embedded web configuration interface, allowing unauthenticated attackers with network access to recover administrative credentials directly from client-side JavaScript and gain full administrative access to the device.
Huawei HG630 V2 Router Authentication Bypass Vulnerability (CVE-2020-37220)
2 rules 1 TTP 1 CVEHuawei HG630 V2 router contains an authentication bypass vulnerability (CVE-2020-37220) that allows unauthenticated attackers to obtain administrative access by retrieving the device serial number via the `/api/system/deviceinfo` endpoint and using the last 8 characters as the default password.
Zyxel WRE6505 v2 Command Injection Vulnerability (CVE-2026-7256)
2 rules 1 TTP 1 CVEA command injection vulnerability (CVE-2026-7256) in Zyxel WRE6505 v2 firmware allows an adjacent attacker on the LAN to execute arbitrary OS commands by sending a crafted HTTP request.
TRENDnet TEW-821DAP Firmware Update Buffer Overflow Vulnerability
2 rules 1 TTP 1 CVEA buffer overflow vulnerability exists in TRENDnet TEW-821DAP version 1.12B01, allowing a remote attacker to execute arbitrary code by manipulating the 'str' argument in the auto_update_firmware function of the Firmware Update component.
Zyxel Command Injection Vulnerabilities in CPE and Extenders
2 rules 1 TTPZyxel released a security advisory on April 28, 2026, addressing command injection vulnerabilities across multiple versions of their 4G LTE/5G NR CPE, DSL/Ethernet CPE, Fiber ONTs, and Wireless Extender products, potentially allowing attackers to execute arbitrary commands.
D-Link DWM-222W USB Wi-Fi Adapter Brute-Force Protection Bypass Vulnerability
2 rules 1 CVED-Link DWM-222W USB Wi-Fi Adapter is vulnerable to brute-force attacks due to a protection bypass, allowing unauthenticated adjacent network attackers to gain control over the device by circumventing login attempt limits.
H3C Magic B0 Router Buffer Overflow Vulnerability (CVE-2026-6560)
2 rules 1 TTP 1 CVEA buffer overflow vulnerability (CVE-2026-6560) in H3C Magic B0 up to 100R002 allows remote attackers to execute arbitrary code by manipulating the 'param' argument in the Edit_BasicSSID function of the /goform/aspForm file.
Totolink A7100RU OS Command Injection Vulnerability (CVE-2026-5677)
2 rules 1 TTP 1 CVEA remote OS command injection vulnerability (CVE-2026-5677) exists in the CsteSystem function of the /cgi-bin/cstecgi.cgi file in Totolink A7100RU firmware version 7.4cu.2313_b20191024 due to improper handling of the resetFlags argument.
Hirschmann EagleSDV Denial-of-Service Vulnerability (CVE-2022-4986)
2 rules 1 TTP 1 CVEHirschmann EagleSDV devices are vulnerable to denial-of-service (DoS) attacks where a device crash can be triggered by establishing TLS 1.0 or TLS 1.1 connections, leading to service disruption.
Linksys MR9600 SmartConnect OS Command Injection (CVE-2026-4558)
2 rules 1 TTPA remote OS command injection vulnerability exists in the Linksys MR9600 router version 2.0.6.206937, allowing attackers to execute arbitrary commands by manipulating specific function arguments via the SmartConnect.lua file.
D-Link DIR-513 Stack-Based Buffer Overflow Vulnerability
2 rules 1 TTPA stack-based buffer overflow vulnerability (CVE-2026-4555) exists in the formEasySetTimezone function of the /goform/formEasySetTimezone file within the boa component of D-Link DIR-513 1.10, allowing remote attackers to execute arbitrary code.
Totolink A8000RU OS Command Injection Vulnerability (CVE-2026-7154)
2 rules 2 TTPs 1 CVEA remote OS command injection vulnerability exists in the Totolink A8000RU router version 7.1cu.643_b20200521, allowing attackers to execute arbitrary commands by manipulating the 'tty_server' argument in the 'setAdvancedInfoShow' function.
Cisco ASA Device File Copy to Remote Location
2 rules 3 TTPsThe analytic detects file copy operations from Cisco ASA devices to remote locations using protocols like TFTP, FTP, HTTP, HTTPS, SMB, or SCP, potentially indicating data exfiltration by threat actors targeting network devices.
DrayTek Vigor 2960 Unauthenticated Remote Command Execution via CVE-2022-50994
2 rules 1 TTP 1 CVEDrayTek Vigor 2960 firmware versions prior to 1.5.1.4 are vulnerable to OS command injection (CVE-2022-50994) in the CGI login handler, allowing unauthenticated remote attackers to execute arbitrary commands by injecting shell metacharacters into the formpassword parameter if the target account has MOTP enabled.