home.social

#iot-security — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #iot-security, aggregated by home.social.

fetched live
  1. CVE-2026-8983: Autel Maxi Charger Single ≤1.03.51 is affected by a CRITICAL flaw — hard-coded token bypasses authentication, exposing management endpoints. Restrict access & monitor for abuse. Patch status unknown. radar.offseq.com/threat/autel- #OffSeq #CVE20268983 #IoTSecurity

  2. CVE-2026-42566 (HIGH): Meshtastic firmware <2.7.23.b246bcd suffers from improper input validation. Malformed User.long_name can poison BLE node DBs, causing iOS sync loops and device loss. Upgrade now. Details: radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE #IoTSecurity

  3. CVE-2026-42566 (HIGH): Meshtastic firmware <2.7.23.b246bcd suffers from improper input validation. Malformed User.long_name can poison BLE node DBs, causing iOS sync loops and device loss. Upgrade now. Details: radar.offseq.com/threat/cve-20 #OffSeq #infosec #CVE #IoTSecurity

  4. CVE-2026-15511 (CRITICAL, CVSS 9.3): OS command injection in Comfast CF-WR631AX V3 (fw 2.7.0.0 – 2.7.0.8) enables unauthenticated remote code execution. No patch. Restrict access & disable remote mgmt. radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoTSecurity #Router

  5. CVE-2026-15481 (HIGH, CVSS 8.7) affects Trendnet TEW-635BRM <=1.00.03: Remote command injection via IPoA WAN setup. Exploit is public. Devices are EOL — replace hardware ASAP. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Infosec #IoTSecurity

  6. wolfSSL: 57 CVEs, 4 critical, 11 high. 70% unpatched. Trust Score: C. CVE trend up 24. Key flaws: CWE-295 (improper cert validation). #wolfSSL #IoTsecurity #cybersecurity

    valtersit.com/vendors/wolfssl/

  7. CVE-2026-13768: Gardyn Home Firmware (CRITICAL, CVSS 10) exposes a privileged iothubowner key, enabling attackers to control devices & move laterally on networks. No patch yet. Monitor and segment IoT devices. radar.offseq.com/threat/cve-20 #OffSeq #IoTSecurity #CVE202613768

  8. CVE-2026-13564: HIGH (CVSS 8.7) stack-based buffer overflow in Edimax EW-7478APC v1.04. Remote exploit via pppUserName; public PoC, no patch. Disable remote access or segment device. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity #CVE202613564

  9. Tenda JD12L routers (fw 16.03.53.23) face HIGH severity stack-based buffer overflow (CVE-2026-13516, CVSS 8.7). Remote code execution possible — exploit code is public. Restrict remote access, monitor endpoints. radar.offseq.com/threat/cve-20 #OffSeq #infosec #IoTSecurity #CVE

  10. H.VIEW HV-500S6 IP Camera has a HIGH severity bug (CVE-2026-55975, CVSS 7.2): Authenticated users may inject commands using unsanitized XML in cert generation. Restrict access, monitor activity, and check for patches. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity 🔒

  11. CVE-2026-56414: H.VIEW HV-500S6 IP Camera has a HIGH-severity vuln (CVSS 7.2) allowing authenticated users to upload arbitrary files via certificate upload, risking persistent compromise. Restrict admin access & monitor uploads. radar.offseq.com/threat/cve-20 #OffSeq #IoTSecurity #CVE #Vulnerability

  12. GeoVision GV-LPC2011/2211 devices (≤1.12) face CRITICAL CVE-2026-57880: stack-based buffer overflow in RTSP auth enables remote, unauthenticated DoS or code execution. Restrict RTSP access, monitor traffic. Patch status unknown. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSecurity #CVE

  13. GeoVision GV-LPC2011/2211 (<=1.12) hit by CVE-2026-57881: CRITICAL stack-based buffer overflow in vlsvr enables unauthenticated RCE or DoS. No patch yet — restrict access & monitor activity. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSecurity #CVE202657881

  14. CVE-2026-12851: CRITICAL OS command injection in GeoVision GV-I/O Box 4E v2.09 via DVRSearch/Network.cgi allows remote code execution. Patch status pending — restrict access & monitor endpoints. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity #CVE #Security

  15. 🔍 HIGH severity: Buffer overflow in GALAYOU Y4 v1.0.0 (CVE-2026-12192). Exploitable via local network — no patch or vendor response yet. Restrict network access & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSecurity #BufferOverflow

  16. Iran built cameras to surveil its people. Israel hacked them, tracked Khamenei's guards for years, and killed him on Feb 28, 2026 with 30 precision strikes. Authoritarianism built the weapon that killed its author. #Unit8200 #IoTsecurity #CyberWar

  17. Iran built cameras to surveil its people. Israel hacked them, tracked Khamenei's guards for years, and killed him on Feb 28, 2026 with 30 precision strikes. Authoritarianism built the weapon that killed its author. #Unit8200 #IoTsecurity #CyberWar

  18. 🛡️ CVE-2026-12187: HIGH severity command injection in GL.iNet GL-MT3000 (fw 4.4.0 – 4.4.5). Remote code execution possible via /usr/bin/one_click_upgrade. Upgrade to v4.7 now! radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity #CVE202612187

  19. 🔍 CVE-2026-12186 (HIGH, CVSS 8.7) hits GL.iNet GL-MT3000 (4.4.0 – 4.4.5): Remote command injection via Tor Proxy config handler. Exploit is public — patch to 4.7 now! radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #Infosec #IoTSecurity

  20. 🚨 CRITICAL: CVE-2026-28742 in Naxclow Smart Doorbell X3 — hard-coded platform-wide key + no replay protection = broad request forgery & device impersonation. No patch yet. Avoid untrusted networks & monitor devices. radar.offseq.com/threat/cve-20 #OffSeq #IoTSecurity #Vuln

  21. ⚠️ CVE-2026-50101 (CRITICAL): Naxclow Smart Doorbell X3 uses static relay credentials, allowing attackers who gain access to maintain persistent control, even after resets. No patch yet. Limit network exposure & monitor advisories. radar.offseq.com/threat/cve-20 #OffSeq #IoTSecurity #CVE202650101

  22. 🚨 CRITICAL: CVE-2026-45328 impacts esp-idf 5.5.4 & 6.0 — improper input validation in esp_tee could enable privilege escalation or disrupt secure hardware ops. Patch to 5.5.5/6.0.1 now! radar.offseq.com/threat/cve-20 #OffSeq #IoTSecurity #CVE202645328

  23. CVE-2026-11451: MEDIUM severity command injection in GL.iNet GL-MT3000 (v4.4.5). 🛡️ Remote attackers can exploit FTP handler via media_dir. Fixed in 4.8.1 — update now! radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #GLiNet #IoTSecurity

  24. ⚠️ HIGH severity: Stack-based buffer overflow in JingDong JD Cloud Box AX6600 v4.5.3.r4546 (CVE-2026-11413). Remote code execution possible. Vendor silent, no patch. Isolate devices & monitor for updates. radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity

  25. 🚨 CVE-2026-6274 (CRITICAL): Redline WR3200 (7.1.3-7.1.7) has improper authentication, allowing full device compromise. No patch yet — restrict access & monitor traffic. Details: radar.offseq.com/threat/cve-20 #OffSeq #CVE #IoTSecurity

  26. 🛑 HIGH: CVE-2026-10161 in TRENDnet TEW-432BRP (v3.10B20) — stack buffer overflow in formResetStatistic can be exploited remotely. No patch — device is EOL. Replace urgently! radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSecurity #CVE2026 #Router

  27. 🔎 CVE-2026-10126: HIGH severity buffer overflow in Edimax BR-6478AC v1.23. Remote code execution or DoS possible; public exploit released. Restrict remote mgmt access & watch for vendor patches. radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSecurity #Infosec

  28. 🛑 CRITICAL: Totolink A8000RU (7.1cu.643_b20200521) is vulnerable (CVE-2026-9478) to remote OS command injection via the web interface. Public exploit available. Restrict access & monitor for patches! radar.offseq.com/threat/cve-20 #OffSeq #CVE20269478 #IoTSecurity #Infosec

  29. 🛡️ CVE-2026-9435: Critical OS command injection in Totolink A8000RU (fw 7.1cu.643_b20200521) allows unauthenticated remote code execution. No patch yet — restrict web UI & monitor advisories. Exploit is public! radar.offseq.com/threat/cve-20 #OffSeq #CVE20269435 #IoTSecurity

  30. Totolink A8000RU (7.1cu.643_b20200521) has a CRITICAL OS command injection vuln (CVE-2026-9406, CVSS 9.3). Exploit public, no patch yet. Restrict web UI, disable remote mgmt, monitor traffic. radar.offseq.com/threat/cve-20 #OffSeq #vuln #IoTSecurity #CVE20269406

  31. CVE-2026-9360: HIGH severity buffer overflow in Edimax EW-7438RPn v1.28a. Remotely exploitable, public exploit released, no patch yet. Disable remote access or isolate! Details: radar.offseq.com/threat/cve-20 #OffSeq #Vuln #IoTSecurity #BufferOverflow

  32. 🚨 HIGH severity (CVSS 8.7): Edimax EW-7438RPn v1.0 – 1.31 stack-based buffer overflow in /goform/mp (webs arg). Remote code execution possible, public exploit out. No vendor patch. Restrict device access! CVE-2026-9348 radar.offseq.com/threat/cve-20 #OffSeq #IoTSecurity #BufferOverflow

  33. The Transportation & Mobility Special Interest Group (#SIG) is building a dedicated space within the FIRST community for collaboration across the #transportation and #mobility industry on cybersecurity challenges in the IT, OT, and #IoT space.

    This practitioner-focused group will help organizations share best practices, improve coordination, and develop more unified approaches to incident response across connected transportation environments and mobility technologies.

    The SIG also aims to advance standards and guidelines development while helping integrate transportation and mobility-focused incident response planning into the broader FIRST framework.

    If you work in transportation security, OT/IoT security, incident response, infrastructure protection, or mobility technology, we encourage you to get involved and help shape this growing community!

    Learn more at: first.org/global/sigs/transpor

    #FIRST #CyberSecurity #TransportationSecurity #OTSecurity #IoTSecurity

  34. 📣 THE COUNTDOWN TO NEXUS IS ON

    Join more than 250 CPS security leaders from global organizations in Washington, DC. as we tackle business resilience in the AI era.

    With the cybersecurity industry at an inflection point, Nexus Conference 2026 is your opportunity to lead the way forward.

    👉 Apply to attend: nexusconference.io

    #Nexus2026 #cybersecurity #OTsecurity #IoTsecurity #industrial #healthcare #publicsector #commercial #AI #artificialintelligence #CISO

  35. 🔒 CVE-2026-7031: HIGH-severity buffer overflow in Tenda F456 (v1.0.0.5). Remote, no user interaction needed. Exploit public, no patch yet. Limit device exposure & monitor for updates. More: radar.offseq.com/threat/cve-20 #OffSeq #Vulnerability #IoTSecurity #NetSec