Tag
#IoT Vulnerability
Critical Buffer Overflow Vulnerability in Tenda HG10: CVE-2026-86165
A critical buffer overflow vulnerability (CVE-2026-86165) has been discovered in the Tenda HG10 device, specifically affecting version 300001138. This vulnerability, with a CVSS score of 9.8, allows remote attackers to exploit the device without authentication, potentially leading to high impacts on confidentiality, integrity, and availability. The exploit has been made public, increasing the risk of active exploitation. Immediate patching or mitigation is strongly recommended.
Understanding and Defending Against CVE-2026-71946: Command Injection in D-Link DWR-M961 Devices
CVE-2026-71946 is a critical command injection vulnerability in D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108. This vulnerability allows a remote attacker to inject arbitrary malicious commands into the host field of the /boafrm/formPingDiagnosticRun interface, resulting in command execution with root privileges. The vulnerability has a CVSS score of 9.8, indicating a high severity. This educational analysis aims to provide a deep understanding of the threat and defensive thinking to protect against such vulnerabilities.
Critical Unauthenticated Command Injection Vulnerability in Puwell IP Camera Firmware
A critical vulnerability, CVE-2026-61515, with a CVSS score of 9.8, was discovered in Puwell IP Camera firmware versions 2.x through 4.x. This vulnerability allows remote attackers to execute arbitrary operating system commands without authentication by sending a crafted JSON payload to the DebugShell interface exposed on TCP port 34567. The vulnerability is caused by a lack of authentication and input sanitization in the binary protocol service, enabling attackers to achieve root-level code execution and complete device compromise. Organizations using affected firmware versions should immediately apply patches or workarounds to prevent exploitation.