#iot-security — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #iot-security, aggregated by home.social.
-
CVE-2026-8983: Autel Maxi Charger Single ≤1.03.51 is affected by a CRITICAL flaw — hard-coded token bypasses authentication, exposing management endpoints. Restrict access & monitor for abuse. Patch status unknown. https://radar.offseq.com/threat/autel-maxi-charger-single-firmware-through-v10351-contains-a-hard-coded-authentication-token-that-cb2fec544a5f031e #OffSeq #CVE20268983 #IoTSecurity
-
CVE-2026-42566 (HIGH): Meshtastic firmware <2.7.23.b246bcd suffers from improper input validation. Malformed User.long_name can poison BLE node DBs, causing iOS sync loops and device loss. Upgrade now. Details: https://radar.offseq.com/threat/cve-2026-42566-cwe-20-improper-input-validation-in-meshtastic-firmware-f4cb4608f8fc25f1 #OffSeq #infosec #CVE #IoTSecurity
-
CVE-2026-42566 (HIGH): Meshtastic firmware <2.7.23.b246bcd suffers from improper input validation. Malformed User.long_name can poison BLE node DBs, causing iOS sync loops and device loss. Upgrade now. Details: https://radar.offseq.com/threat/cve-2026-42566-cwe-20-improper-input-validation-in-meshtastic-firmware-f4cb4608f8fc25f1 #OffSeq #infosec #CVE #IoTSecurity
-
CVE-2026-15511 (CRITICAL, CVSS 9.3): OS command injection in Comfast CF-WR631AX V3 (fw 2.7.0.0 – 2.7.0.8) enables unauthenticated remote code execution. No patch. Restrict access & disable remote mgmt. https://radar.offseq.com/threat/cve-2026-15511-os-command-injection-in-comfast-cf--f966bd818b8c5835 #OffSeq #CVE #IoTSecurity #Router
-
CVE-2026-15481 (HIGH, CVSS 8.7) affects Trendnet TEW-635BRM <=1.00.03: Remote command injection via IPoA WAN setup. Exploit is public. Devices are EOL — replace hardware ASAP. https://radar.offseq.com/threat/cve-2026-15481-command-injection-in-trendnet-tew-6-0618f5678477012c #OffSeq #Vulnerability #Infosec #IoTSecurity
-
wolfSSL: 57 CVEs, 4 critical, 11 high. 70% unpatched. Trust Score: C. CVE trend up 24. Key flaws: CWE-295 (improper cert validation). #wolfSSL #IoTsecurity #cybersecurity
-
CVE-2026-13768: Gardyn Home Firmware (CRITICAL, CVSS 10) exposes a privileged iothubowner key, enabling attackers to control devices & move laterally on networks. No patch yet. Monitor and segment IoT devices. https://radar.offseq.com/threat/cve-2026-13768-cwe-798-in-gardyn-gardyn-home-firmw-08332214fc38f3ba #OffSeq #IoTSecurity #CVE202613768
-
CVE-2026-13564: HIGH (CVSS 8.7) stack-based buffer overflow in Edimax EW-7478APC v1.04. Remote exploit via pppUserName; public PoC, no patch. Disable remote access or segment device. https://radar.offseq.com/threat/cve-2026-13564-stack-based-buffer-overflow-in-edim-026db0243354aebd #OffSeq #Vulnerability #IoTSecurity #CVE202613564
-
Tenda JD12L routers (fw 16.03.53.23) face HIGH severity stack-based buffer overflow (CVE-2026-13516, CVSS 8.7). Remote code execution possible — exploit code is public. Restrict remote access, monitor endpoints. https://radar.offseq.com/threat/cve-2026-13516-stack-based-buffer-overflow-in-tend-c61568839c0ead88 #OffSeq #infosec #IoTSecurity #CVE
-
H.VIEW HV-500S6 IP Camera has a HIGH severity bug (CVE-2026-55975, CVSS 7.2): Authenticated users may inject commands using unsanitized XML in cert generation. Restrict access, monitor activity, and check for patches. https://radar.offseq.com/threat/cve-2026-55975-cwe-78-in-hview-hv-500s6-ip-camera-32fd47fcf53b8f7c #OffSeq #Vulnerability #IoTSecurity 🔒
-
CVE-2026-56414: H.VIEW HV-500S6 IP Camera has a HIGH-severity vuln (CVSS 7.2) allowing authenticated users to upload arbitrary files via certificate upload, risking persistent compromise. Restrict admin access & monitor uploads. https://radar.offseq.com/threat/cve-2026-56414-cwe-434-in-hview-hv-500s6-ip-camera-2fc4d58c6ce82381 #OffSeq #IoTSecurity #CVE #Vulnerability
-
GeoVision GV-LPC2011/2211 devices (≤1.12) face CRITICAL CVE-2026-57880: stack-based buffer overflow in RTSP auth enables remote, unauthenticated DoS or code execution. Restrict RTSP access, monitor traffic. Patch status unknown. https://radar.offseq.com/threat/cve-2026-57880-cwe-121-stack-based-buffer-overflow-1d88eee9b47ed7bb #OffSeq #Vuln #IoTSecurity #CVE
-
GeoVision GV-LPC2011/2211 (<=1.12) hit by CVE-2026-57881: CRITICAL stack-based buffer overflow in vlsvr enables unauthenticated RCE or DoS. No patch yet — restrict access & monitor activity. https://radar.offseq.com/threat/cve-2026-57881-cwe-121-stack-based-buffer-overflow-0de9014b0e3f1945 #OffSeq #Vuln #IoTSecurity #CVE202657881
-
CVE-2026-12851: CRITICAL OS command injection in GeoVision GV-I/O Box 4E v2.09 via DVRSearch/Network.cgi allows remote code execution. Patch status pending — restrict access & monitor endpoints. https://radar.offseq.com/threat/cve-2026-12851-cwe-78-improper-neutralization-of-s-3964552d83f5f479 #OffSeq #Vulnerability #IoTSecurity #CVE #Security
-
🔍 HIGH severity: Buffer overflow in GALAYOU Y4 v1.0.0 (CVE-2026-12192). Exploitable via local network — no patch or vendor response yet. Restrict network access & monitor for updates. https://radar.offseq.com/threat/cve-2026-12192-buffer-overflow-in-galayou-y4-555d7b50 #OffSeq #Vuln #IoTSecurity #BufferOverflow
-
Iran built cameras to surveil its people. Israel hacked them, tracked Khamenei's guards for years, and killed him on Feb 28, 2026 with 30 precision strikes. Authoritarianism built the weapon that killed its author. #Unit8200 #IoTsecurity #CyberWar
-
Iran built cameras to surveil its people. Israel hacked them, tracked Khamenei's guards for years, and killed him on Feb 28, 2026 with 30 precision strikes. Authoritarianism built the weapon that killed its author. #Unit8200 #IoTsecurity #CyberWar
-
🛡️ CVE-2026-12187: HIGH severity command injection in GL.iNet GL-MT3000 (fw 4.4.0 – 4.4.5). Remote code execution possible via /usr/bin/one_click_upgrade. Upgrade to v4.7 now! https://radar.offseq.com/threat/cve-2026-12187-command-injection-in-glinet-gl-mt30-4b35174f #OffSeq #Vulnerability #IoTSecurity #CVE202612187
-
🔍 CVE-2026-12186 (HIGH, CVSS 8.7) hits GL.iNet GL-MT3000 (4.4.0 – 4.4.5): Remote command injection via Tor Proxy config handler. Exploit is public — patch to 4.7 now! https://radar.offseq.com/threat/cve-2026-12186-command-injection-in-glinet-gl-mt30-8e4f5f3d #OffSeq #Vulnerability #Infosec #IoTSecurity
-
🚨 CRITICAL: CVE-2026-28742 in Naxclow Smart Doorbell X3 — hard-coded platform-wide key + no replay protection = broad request forgery & device impersonation. No patch yet. Avoid untrusted networks & monitor devices. https://radar.offseq.com/threat/cve-2026-28742-cwe-321-use-of-hard-coded-cryptogra-637b7b61 #OffSeq #IoTSecurity #Vuln
-
⚠️ CVE-2026-50101 (CRITICAL): Naxclow Smart Doorbell X3 uses static relay credentials, allowing attackers who gain access to maintain persistent control, even after resets. No patch yet. Limit network exposure & monitor advisories. https://radar.offseq.com/threat/cve-2026-50101-cwe-262-not-using-password-aging-in-f27f494a #OffSeq #IoTSecurity #CVE202650101
-
🚨 CRITICAL: CVE-2026-45328 impacts esp-idf 5.5.4 & 6.0 — improper input validation in esp_tee could enable privilege escalation or disrupt secure hardware ops. Patch to 5.5.5/6.0.1 now! https://radar.offseq.com/threat/cve-2026-45328-cwe-20-improper-input-validation-in-93c234d5 #OffSeq #IoTSecurity #CVE202645328
-
CVE-2026-11451: MEDIUM severity command injection in GL.iNet GL-MT3000 (v4.4.5). 🛡️ Remote attackers can exploit FTP handler via media_dir. Fixed in 4.8.1 — update now! https://radar.offseq.com/threat/cve-2026-11451-command-injection-in-glinet-gl-mt30-53c0e750 #OffSeq #Vulnerability #GLiNet #IoTSecurity
-
⚠️ HIGH severity: Stack-based buffer overflow in JingDong JD Cloud Box AX6600 v4.5.3.r4546 (CVE-2026-11413). Remote code execution possible. Vendor silent, no patch. Isolate devices & monitor for updates. https://radar.offseq.com/threat/cve-2026-11413-stack-based-buffer-overflow-in-jing-2be3fa19 #OffSeq #Vulnerability #IoTSecurity
-
🚨 CVE-2026-6274 (CRITICAL): Redline WR3200 (7.1.3-7.1.7) has improper authentication, allowing full device compromise. No patch yet — restrict access & monitor traffic. Details: https://radar.offseq.com/threat/cve-2026-6274-cwe-287-improper-authentication-in-d-2d921cba #OffSeq #CVE #IoTSecurity
-
GitHub - nnonickreal/openqore: unleash the full power of your soundcores! :)
https://github.com/nnonickreal/openqore
Read on HackerWorkspace: https://hackerworkspace.com/article/github-nnonickreal-openqore-unleash-the-full-power-of-your-soundcores
-
🛑 HIGH: CVE-2026-10161 in TRENDnet TEW-432BRP (v3.10B20) — stack buffer overflow in formResetStatistic can be exploited remotely. No patch — device is EOL. Replace urgently! https://radar.offseq.com/threat/cve-2026-10161-stack-based-buffer-overflow-in-tren-3a604145 #OffSeq #Vuln #IoTSecurity #CVE2026 #Router
-
🔎 CVE-2026-10126: HIGH severity buffer overflow in Edimax BR-6478AC v1.23. Remote code execution or DoS possible; public exploit released. Restrict remote mgmt access & watch for vendor patches. https://radar.offseq.com/threat/cve-2026-10126-buffer-overflow-in-edimax-br-6478ac-b8a1eb66 #OffSeq #Vuln #IoTSecurity #Infosec
-
🛑 CRITICAL: Totolink A8000RU (7.1cu.643_b20200521) is vulnerable (CVE-2026-9478) to remote OS command injection via the web interface. Public exploit available. Restrict access & monitor for patches! https://radar.offseq.com/threat/cve-2026-9478-os-command-injection-in-totolink-a80-020b39d8 #OffSeq #CVE20269478 #IoTSecurity #Infosec
-
🛡️ CVE-2026-9435: Critical OS command injection in Totolink A8000RU (fw 7.1cu.643_b20200521) allows unauthenticated remote code execution. No patch yet — restrict web UI & monitor advisories. Exploit is public! https://radar.offseq.com/threat/cve-2026-9435-os-command-injection-in-totolink-a80-a8a549f3 #OffSeq #CVE20269435 #IoTSecurity
-
Totolink A8000RU (7.1cu.643_b20200521) has a CRITICAL OS command injection vuln (CVE-2026-9406, CVSS 9.3). Exploit public, no patch yet. Restrict web UI, disable remote mgmt, monitor traffic. https://radar.offseq.com/threat/cve-2026-9406-os-command-injection-in-totolink-a80-bbf9cf37 #OffSeq #vuln #IoTSecurity #CVE20269406
-
CVE-2026-9360: HIGH severity buffer overflow in Edimax EW-7438RPn v1.28a. Remotely exploitable, public exploit released, no patch yet. Disable remote access or isolate! Details: https://radar.offseq.com/threat/cve-2026-9360-buffer-overflow-in-edimax-ew-7438rpn-4e6fd99f #OffSeq #Vuln #IoTSecurity #BufferOverflow
-
🚨 HIGH severity (CVSS 8.7): Edimax EW-7438RPn v1.0 – 1.31 stack-based buffer overflow in /goform/mp (webs arg). Remote code execution possible, public exploit out. No vendor patch. Restrict device access! CVE-2026-9348 https://radar.offseq.com/threat/cve-2026-9348-stack-based-buffer-overflow-in-edima-d83420d9 #OffSeq #IoTSecurity #BufferOverflow
-
Patch Now: Critical Flaw in OT Robot OS Gives Attackers Control
https://www.darkreading.com/ics-ot-security/patch-now-critical-flaw-ot-robot-os
Read on HackerWorkspace: https://hackerworkspace.com/article/patch-now-critical-flaw-in-ot-robot-os-gives-attackers-control
-
Inside the Secret World of DEF CON Hackers | VICE: Motherboard | Blueprint
-
The Transportation & Mobility Special Interest Group (#SIG) is building a dedicated space within the FIRST community for collaboration across the #transportation and #mobility industry on cybersecurity challenges in the IT, OT, and #IoT space.
This practitioner-focused group will help organizations share best practices, improve coordination, and develop more unified approaches to incident response across connected transportation environments and mobility technologies.
The SIG also aims to advance standards and guidelines development while helping integrate transportation and mobility-focused incident response planning into the broader FIRST framework.
If you work in transportation security, OT/IoT security, incident response, infrastructure protection, or mobility technology, we encourage you to get involved and help shape this growing community!
Learn more at: https://www.first.org/global/sigs/transport/
#FIRST #CyberSecurity #TransportationSecurity #OTSecurity #IoTSecurity
-
📣 THE COUNTDOWN TO NEXUS IS ON
Join more than 250 CPS security leaders from global organizations in Washington, DC. as we tackle business resilience in the AI era.
With the cybersecurity industry at an inflection point, Nexus Conference 2026 is your opportunity to lead the way forward.
👉 Apply to attend: https://nexusconference.io
#Nexus2026 #cybersecurity #OTsecurity #IoTsecurity #industrial #healthcare #publicsector #commercial #AI #artificialintelligence #CISO
-
Defending consumer web properties against modern DDoS attacks | Microsoft Security Blog
Read on HackerWorkspace: https://hackerworkspace.com/article/defending-consumer-web-properties-against-modern-ddos-attacks-microsoft-security-blog
-
LABScon25 Replay | Connect to the Foreign Entity to Enhance Your User Experience | FitzPatrick
-
This 'cardputer' sits between the Raspberry Pi and Flipper Zero - but it's uniquely better
https://www.zdnet.com/article/m5stack-cardputer-adv-review/
Read on HackerWorkspace: https://hackerworkspace.com/article/this-cardputer-sits-between-the-raspberry-pi-and-flipper-zero-but-it-s-uniquely-better
-
Tracking a Drone Indoors Without GPS | ESP32 BLE RSSI
-
I Tried Building a Cheap Indoor Positioning System… So I Built a Drone Instead - CiferTech
https://cifertech.net/i-tried-building-a-cheap-indoor-positioning-system-so-i-built-a-drone-instead/
Read on HackerWorkspace: https://hackerworkspace.com/article/i-tried-building-a-cheap-indoor-positioning-system-so-i-built-a-drone-instead-cifertech
-
HackRF PortaPack Splash Screen Without Removing the SD Card
-
Giving my Raspberry Pi LTE Connectivity - 4G LTE IoT Test Lab
-
The Internet Knows Who You Are — Even Offline
-
🔒 CVE-2026-7031: HIGH-severity buffer overflow in Tenda F456 (v1.0.0.5). Remote, no user interaction needed. Exploit public, no patch yet. Limit device exposure & monitor for updates. More: https://radar.offseq.com/threat/cve-2026-7031-buffer-overflow-in-tenda-f456-f28ef6c0 #OffSeq #Vulnerability #IoTSecurity #NetSec
-
Open-Source AI Assisted Firmware Analysis - WAIRZ
-
DeskUp Pro smart standing desk controller integrates with Home Assistant and Homey Pro Smart Home hubs - CNX Software
Read on HackerWorkspace: https://hackerworkspace.com/article/deskup-pro-smart-standing-desk-controller-integrates-with-home-assistant-and-homey-pro-smart-home-hubs-cnx-software
-
Critical flaw in wolfSSL library enables forged certificate use
Read on HackerWorkspace: https://hackerworkspace.com/article/critical-flaw-in-wolfssl-library-enables-forged-certificate-use
-
The Rise of Autonomous Drone Swarms | VICE: Cyberwar | Blueprint