Tag
Critical Vulnerability in VMware Aria Operations for Networks (CVE-2023-34039)
1 rule 2 TTPs 1 CVEVMware Aria Operations for Networks versions 6.0 to 6.10 contain a vulnerability involving static SSH keys that allow unauthorized remote access and root-level privilege escalation.
Remote Command Injection in TOTOLINK NR1800X
1 rule 1 TTP 1 CVEThe TOTOLINK NR1800X router is vulnerable to remote command injection via the setUssd function in cgi-bin/cstecgi.cgi, enabling unauthenticated attackers to execute arbitrary system commands.
Exploitation of CVE-2018-14847 in MikroTik RouterOS
1 rule 2 TTPs 1 CVEAn unauthenticated remote file read vulnerability in MikroTik RouterOS (CVE-2018-14847) allows attackers to extract and decrypt administrative credentials, leading to full system compromise.
Command Injection Vulnerability in DrayTek VigorSwitch
2 TTPs 1 CVEAuthenticated attackers can exploit a command injection flaw in the DrayTek VigorSwitch commandTable function to achieve root-level remote code execution.
Critical OS Command Injection in DrayTek VigorSwitch
1 rule 3 TTPs 1 CVEMultiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability (CVE-2026-71921) in the setget.cgi interface that allows unauthenticated remote attackers to execute arbitrary commands as root.
Critical Vulnerabilities in Citrix NetScaler ADC and Gateway
2 CVEsCitrix has released patches for critical vulnerabilities including CVE-2026-19490, an authentication bypass, and CVE-2026-19489, a memory overflow vulnerability affecting NetScaler ADC and Gateway appliances.
Command Injection Vulnerability in COMFAST CF-N1-S
3 rules 2 TTPs 1 CVEA critical command injection vulnerability (CVE-2026-75094) in the COMFAST CF-N1-S CGI interface allows remote, authenticated attackers to execute arbitrary OS commands via the 'ssid' parameter.
Authorization Bypass in GL.iNet WebDAV Service
1 rule 2 TTPs 1 CVEMultiple GL.iNet router models running firmware versions up to 4.8.x contain an authorization bypass vulnerability in the WebDAV service, allowing remote unauthenticated attackers to manipulate file operations.
Remote Stack-Based Buffer Overflow in Tenda W20E
2 rules 3 TTPs 1 CVEA stack-based buffer overflow vulnerability in Tenda W20E firmware allows authenticated remote attackers to achieve potential code execution via the QoS Edit component.
Open vSwitch GSO Userspace Truncation Underflow Vulnerability
1 CVECVE-2026-68123 is a vulnerability in Open vSwitch related to GSO userspace truncation that may cause an underflow condition during packet processing, potentially impacting memory or system stability.
Command Injection in Zyxel WAX650S export-cgi
1 rule 1 TTP 1 CVEAn authenticated administrator can exploit a command injection vulnerability in the export-cgi program of Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 to execute arbitrary OS commands.
Remote Stack-Based Buffer Overflow in Wavlink Networking Devices
1 TTP 1 CVE 1 IOCMultiple Wavlink networking devices are vulnerable to a remote stack-based buffer overflow in the lighttpd component due to insecure use of strcpy in the upload.cgi script via the HTTP_COOKIE header.
Internet Systems Consortium BIND: Multiple Vulnerabilities
3 TTPsMultiple vulnerabilities in Internet Systems Consortium BIND allow an anonymous, remote attacker to bypass security measures, manipulate data, disclose confidential information, or trigger a Denial-of-Service condition, potentially leading to compromise of data integrity, confidentiality, and availability of the DNS service.