Skip to content
Threat Feed

Tag

Network-Infrastructure

13 briefs RSS
critical advisory

Critical Vulnerability in VMware Aria Operations for Networks (CVE-2023-34039)

VMware Aria Operations for Networks versions 6.0 to 6.10 contain a vulnerability involving static SSH keys that allow unauthorized remote access and root-level privilege escalation.

Aria Operations for Networks vulnerability remote-code-execution network-infrastructure
1r 2t 1c
high advisory

Remote Command Injection in TOTOLINK NR1800X

The TOTOLINK NR1800X router is vulnerable to remote command injection via the setUssd function in cgi-bin/cstecgi.cgi, enabling unauthenticated attackers to execute arbitrary system commands.

NR1800X remote-code-execution command-injection network-infrastructure
1r 1t 1c
high advisory

Exploitation of CVE-2018-14847 in MikroTik RouterOS

An unauthenticated remote file read vulnerability in MikroTik RouterOS (CVE-2018-14847) allows attackers to extract and decrypt administrative credentials, leading to full system compromise.

RouterOS +1 vulnerability credential-access network-infrastructure
1r 2t 1c
high advisory

Command Injection Vulnerability in DrayTek VigorSwitch

Authenticated attackers can exploit a command injection flaw in the DrayTek VigorSwitch commandTable function to achieve root-level remote code execution.

VigorSwitch vulnerability remote-code-execution network-infrastructure
2t 1c
critical advisory

Critical OS Command Injection in DrayTek VigorSwitch

Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability (CVE-2026-71921) in the setget.cgi interface that allows unauthenticated remote attackers to execute arbitrary commands as root.

VigorSwitch G2540xs +10 vulnerability remote-code-execution network-infrastructure cve network-security network hardware
1r 3t 1c
high advisory

Critical Vulnerabilities in Citrix NetScaler ADC and Gateway

Citrix has released patches for critical vulnerabilities including CVE-2026-19490, an authentication bypass, and CVE-2026-19489, a memory overflow vulnerability affecting NetScaler ADC and Gateway appliances.

PoC NetScaler ADC +3 vulnerability network-infrastructure authentication-bypass
2c updated
critical advisory

Command Injection Vulnerability in COMFAST CF-N1-S

A critical command injection vulnerability (CVE-2026-75094) in the COMFAST CF-N1-S CGI interface allows remote, authenticated attackers to execute arbitrary OS commands via the 'ssid' parameter.

CF-N1-S vulnerability rce network-infrastructure
3r 2t 1c updated
high advisory

Authorization Bypass in GL.iNet WebDAV Service

Multiple GL.iNet router models running firmware versions up to 4.8.x contain an authorization bypass vulnerability in the WebDAV service, allowing remote unauthenticated attackers to manipulate file operations.

A1300 +16 cve-2026-19980 remote-code-execution network-security firmware-vulnerability vulnerability rce network-infrastructure
1r 2t 1c
high advisory

Remote Stack-Based Buffer Overflow in Tenda W20E

A stack-based buffer overflow vulnerability in Tenda W20E firmware allows authenticated remote attackers to achieve potential code execution via the QoS Edit component.

W20E cve-2026-19822 vulnerability remote-code-execution cve-2026-19823 buffer-overflow rce network-infrastructure
2r 3t 1c
medium advisory

Open vSwitch GSO Userspace Truncation Underflow Vulnerability

CVE-2026-68123 is a vulnerability in Open vSwitch related to GSO userspace truncation that may cause an underflow condition during packet processing, potentially impacting memory or system stability.

Open vSwitch vulnerability network-infrastructure product-news
1c
high advisory

Command Injection in Zyxel WAX650S export-cgi

An authenticated administrator can exploit a command injection vulnerability in the export-cgi program of Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 to execute arbitrary OS commands.

PoC WAX650S firmware +1 cve command-injection zyxel network-infrastructure
1r 1t 1c updated
high advisory

Remote Stack-Based Buffer Overflow in Wavlink Networking Devices

Multiple Wavlink networking devices are vulnerable to a remote stack-based buffer overflow in the lighttpd component due to insecure use of strcpy in the upload.cgi script via the HTTP_COOKIE header.

WN572 +10 vulnerability rce network-infrastructure
1t 1c 1i
medium advisory

Internet Systems Consortium BIND: Multiple Vulnerabilities

Multiple vulnerabilities in Internet Systems Consortium BIND allow an anonymous, remote attacker to bypass security measures, manipulate data, disclose confidential information, or trigger a Denial-of-Service condition, potentially leading to compromise of data integrity, confidentiality, and availability of the DNS service.

BIND dns vulnerability denial-of-service data-manipulation information-disclosure network-infrastructure
3t