![]() |
June 8th, 2025 (about 1 month ago)
|
![]() |
Description: A new variant of the Mirai malware botnet is exploiting a command injection vulnerability in TBK DVR-4104 and DVR-4216 digital video recording devices to hijack them. [...]
June 8th, 2025 (about 1 month ago)
|
CVE-2025-5847 |
Description: A vulnerability has been found in Tenda AC9 15.03.02.13 and classified as critical. Affected by this vulnerability is the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg of the component HTTP POST Request Handler. The manipulation of the argument remoteIp leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. In Tenda AC9 15.03.02.13 wurde eine Schwachstelle gefunden. Sie wurde als kritisch eingestuft. Dabei geht es um die Funktion formSetSafeWanWebMan der Datei /goform/SetRemoteWebCfg der Komponente HTTP POST Request Handler. Durch das Manipulieren des Arguments remoteIp mit unbekannten Daten kann eine stack-based buffer overflow-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.
CVSS: HIGH (8.8) EPSS Score: 0.09%
June 8th, 2025 (about 1 month ago)
|
![]() |
Description: Cybersecurity researchers have flagged a supply chain attack targeting over a dozen packages associated with GlueStack to deliver malware.
The malware, introduced via a change to "lib/commonjs/index.js," allows an attacker to run shell commands, take screenshots, and upload files to infected machines, Aikido Security told The Hacker News, stating these packages collectively account for nearly 1
June 8th, 2025 (about 1 month ago)
|
![]() |
June 8th, 2025 (about 1 month ago)
|
CVE-2025-27563 |
Description: in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.
CVSS: LOW (3.3) EPSS Score: 0.01%
June 8th, 2025 (about 1 month ago)
|
CVE-2025-27247 |
Description: in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.
CVSS: MEDIUM (5.5) EPSS Score: 0.01%
June 8th, 2025 (about 1 month ago)
|
CVE-2025-27242 |
Description: in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.
CVSS: LOW (3.3) EPSS Score: 0.02%
June 8th, 2025 (about 1 month ago)
|
CVE-2025-27131 |
Description: in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.
CVSS: MEDIUM (6.1) EPSS Score: 0.02%
June 8th, 2025 (about 1 month ago)
|
CVE-2025-26693 |
Description: in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.
CVSS: LOW (3.3) EPSS Score: 0.01%
June 8th, 2025 (about 1 month ago)
|