CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

Threat and Vulnerability Intelligence Database

RSS Feed

Example Searches:

Source: TheRegister
June 8th, 2025 (about 1 month ago)
Description: A new variant of the Mirai malware botnet is exploiting a command injection vulnerability in TBK DVR-4104 and DVR-4216 digital video recording devices to hijack them. [...]
Source: BleepingComputer
June 8th, 2025 (about 1 month ago)

CVE-2025-5847

Description: A vulnerability has been found in Tenda AC9 15.03.02.13 and classified as critical. Affected by this vulnerability is the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg of the component HTTP POST Request Handler. The manipulation of the argument remoteIp leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. In Tenda AC9 15.03.02.13 wurde eine Schwachstelle gefunden. Sie wurde als kritisch eingestuft. Dabei geht es um die Funktion formSetSafeWanWebMan der Datei /goform/SetRemoteWebCfg der Komponente HTTP POST Request Handler. Durch das Manipulieren des Arguments remoteIp mit unbekannten Daten kann eine stack-based buffer overflow-Schwachstelle ausgenutzt werden. Die Umsetzung des Angriffs kann dabei über das Netzwerk erfolgen. Der Exploit steht zur öffentlichen Verfügung.

CVSS: HIGH (8.8)

EPSS Score: 0.09%

Source: CVE
June 8th, 2025 (about 1 month ago)
Description: Cybersecurity researchers have flagged a supply chain attack targeting over a dozen packages associated with GlueStack to deliver malware. The malware, introduced via a change to "lib/commonjs/index.js," allows an attacker to run shell commands, take screenshots, and upload files to infected machines, Aikido Security told The Hacker News, stating these packages collectively account for nearly 1
Source: TheHackerNews
June 8th, 2025 (about 1 month ago)
Source: TheRegister
June 8th, 2025 (about 1 month ago)

CVE-2025-27563

Description: in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

CVSS: LOW (3.3)

EPSS Score: 0.01%

Source: CVE
June 8th, 2025 (about 1 month ago)

CVE-2025-27247

Description: in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

CVSS: MEDIUM (5.5)

EPSS Score: 0.01%

Source: CVE
June 8th, 2025 (about 1 month ago)

CVE-2025-27242

Description: in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

CVSS: LOW (3.3)

EPSS Score: 0.02%

Source: CVE
June 8th, 2025 (about 1 month ago)

CVE-2025-27131

Description: in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.

CVSS: MEDIUM (6.1)

EPSS Score: 0.02%

Source: CVE
June 8th, 2025 (about 1 month ago)

CVE-2025-26693

Description: in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.

CVSS: LOW (3.3)

EPSS Score: 0.01%

Source: CVE
June 8th, 2025 (about 1 month ago)