home.social

#tenda β€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #tenda, aggregated by home.social.

  1. πŸ”΄ CVE-2026-89689 - Critical (9.8)

    In the Linux kernel, the following vulnerability has been resolved:

    nfsd: don't free session slots that are still in use

    nfsd4_sequence() can free the very slot it is currently processing.
    When the session shrinker has reduced se_target_maxslots...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  2. πŸ”΄ CVE-2026-89688 - Critical (9.8)

    In the Linux kernel, the following vulnerability has been resolved:

    nfsd: drop the stateid, not the stateowner, on seqid_op replay retry

    In nfs4_preprocess_seqid_op() the stateid is obtained from
    nfsd4_lookup_stateid(), which holds a reference o...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  3. 🟠 CVE-2026-89687 - High (7.5)

    In the Linux kernel, the following vulnerability has been resolved:

    nfsd: ensure nfsd_file_do_acquire() does not use a non-opened file

    ->atomic_open is permitted to return success without actually opening
    the file. It indicates this by calling ...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  4. πŸ”΄ CVE-2026-89686 - Critical (9.8)

    In the Linux kernel, the following vulnerability has been resolved:

    nfsd: fix BUG_ON in nfsd4_alloc_layout_stateid on racing delegation revoke

    nfsd4_alloc_layout_stateid reads fp->fi_deleg_file without holding
    fi_lock when the parent stateid is ...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  5. 🟠 CVE-2026-89685 - High (7.5)

    In the Linux kernel, the following vulnerability has been resolved:

    nfsd: fix clock domain mismatch in clients_still_reclaiming()

    clients_still_reclaiming() computes a deadline from nn->boot_time
    (CLOCK_REALTIME, ~1.7 billion) but compares it ag...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  6. πŸ”΄ CVE-2026-81648 - Critical (10)

    The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the server...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  7. πŸ”΄ CVE-2026-90680 - Critical (9.9)

    A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gateway re...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  8. 🟠 CVE-2026-74933 - High (8.8)

    The GenieWords WordPress plugin from 1.5.27 to 1.5.34 does not have authorisation checks on some of its REST API and AJAX actions, and decodes stored values before printing them, allowing unauthenticated users to overwrite its configuration and in...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  9. 🟠 CVE-2026-37008 - High (8.1)

    CrewAI before fb2323b offers a Python blocklist approach that operates at the wrong level of abstraction, a different vulnerability than CVE-2026-2275. Import-time blocking of module names does not address the availability of Python's complete obj...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  10. 🟠 CVE-2026-88802 - High (7.5)

    The MDJM Event Management WordPress plugin before 1.7.8.5 and the Mobile Events Manager WordPress plugin through 1.4.8.3 do not check a capability, a nonce or the type of the record before permanently deleting the post identified in a request to t...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  11. 🟠 CVE-2026-88793 - High (8.8)

    The YouTube Embed WordPress plugin from 10.0 to 10.3 does not perform any authorisation check on one of its AJAX actions, relying only on a nonce it prints on every front-end page, and does not escape the stored data before rendering it, allowing ...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  12. πŸ”΄ CVE-2026-90607 - Critical (9.9)

    A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. The atta...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  13. πŸ”΄ CVE-2026-90608 - Critical (9.9)

    A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is possible...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  14. 🟠 CVE-2026-23789 - High (7.8)

    An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC encoder driv...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  15. 🟠 CVE-2026-33963 - High (7.5)

    An issue was discovered in camera in Samsung Mobile Processor Exynos 1330, 1380, 1480, 2400, 1580, 2500, 2600, and 1680. A stack-based buffer overflow occurs when a malformed message is sent to the camera driver, causing a denial of service.

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  16. 🟠 CVE-2026-31278 - High (7.7)

    An issue in the /api/v2/setting/adserversetting endpoint of Suprema BioStar 2 before 2.9.12 and and BioStar X before 1.0.2 allows attackers to obtain Active Directory service account credentials in cleartext by supplying a crafted GET request.

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  17. πŸ”΄ CVE-2026-90606 - Critical (9.9)

    A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer ov...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  18. πŸ”΄ CVE-2026-90606 - Critical (9.9)

    A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer ov...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  19. πŸ”΄ CVE-2026-90606 - Critical (9.9)

    A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer ov...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  20. πŸ”΄ CVE-2026-90606 - Critical (9.9)

    A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to buffer ov...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  21. πŸ”΄ CVE-2026-90605 - Critical (9.9)

    A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overf...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  22. πŸ”΄ CVE-2026-90605 - Critical (9.9)

    A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overf...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  23. πŸ”΄ CVE-2026-90605 - Critical (9.9)

    A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overf...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  24. πŸ”΄ CVE-2026-90605 - Critical (9.9)

    A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffer overf...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  25. 🟠 CVE-2026-85129 - High (8.8)

    The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated ...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  26. 🟠 CVE-2026-85129 - High (8.8)

    The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated ...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  27. 🟠 CVE-2026-85129 - High (8.8)

    The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated ...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  28. 🟠 CVE-2026-85129 - High (8.8)

    The Hoo Companion WordPress plugin 1.0.2 does not have any authorisation or validation checks in one of its import features, and does not sanitise the data submitted to it before storing it as the active theme's settings, allowing unauthenticated ...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  29. 🟠 CVE-2026-15891 - High (7.5)

    The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result....

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  30. 🟠 CVE-2026-15891 - High (7.5)

    The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result....

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  31. 🟠 CVE-2026-15891 - High (7.5)

    The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result....

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  32. 🟠 CVE-2026-15891 - High (7.5)

    The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next) but discarded the result....

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  33. πŸ”΄ CVE-2026-89613 - Critical (9.8)

    In the Linux kernel, the following vulnerability has been resolved:

    ntfs: reject invalid empty mapping pairs

    Reject an attribute with empty mapping pairs if it has inconsistent
    highest VCN and size.

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  34. πŸ”΄ CVE-2026-89612 - Critical (9.8)

    In the Linux kernel, the following vulnerability has been resolved:

    ntfs: reject invalid MFT LCNs from boot sector

    The NTFS boot sector stores the MFT and MFTMirr locations as unsigned
    64-bit LCNs, but parse_ntfs_boot_sector() decoded them into ...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  35. πŸ”΄ CVE-2026-89611 - Critical (9.8)

    In the Linux kernel, the following vulnerability has been resolved:

    ntfs: validate non-resident attribute offsets

    ntfs_attr_update_meta() shifts the attribute name when converting between
    non-sparse and sparse attributes. Converting to sparse al...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  36. 🟠 CVE-2026-29811 - High (7.7)

    CyberPanel before 2.4.4 attempts to detect an "alais" domain (i.e., a second domain that serves the same content as a primary domain; normally spelled "alias") via an ORM query filter rather than a Python "if" statement.

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  37. 🟠 CVE-2026-89684 - High (7.5)

    In the Linux kernel, the following vulnerability has been resolved:

    nfsd: fix cpntf publish race in nfs4_init_cp_state

    nfs4_alloc_init_cpntf_state() published the new cpntf entry into the
    s2s_cp_stateids IDR (with cs_type set) in one s2s_cp_lock...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  38. 🟠 CVE-2026-89682 - High (8.1)

    In the Linux kernel, the following vulnerability has been resolved:

    nfsd: fix fcache_disposal UAF by inlining dispose state into nfsd_net

    nfsd_file_dispose_list_delayed() defers fput() to nfsd service threads
    via a per-net freeme queue, preventi...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  39. πŸ”΄ CVE-2026-89697 - Critical (9.1)

    In the Linux kernel, the following vulnerability has been resolved:

    nfsd: add fh_want_write() for early-verified SETATTR in nfsd_proc_setattr()

    The BOTH_TIME_SET branch calls fh_verify() early so setattr_prepare()
    can inspect the dentry. This ca...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  40. 🟠 CVE-2026-89696 - High (7.5)

    In the Linux kernel, the following vulnerability has been resolved:

    nfsd: block non-SAVEFH ops after FOREIGN PUTFH to prevent NULL deref

    When CONFIG_NFSD_V4_2_INTER_SSC is enabled, nfsd4_putfh() can return
    success with fh_dentry and fh_export bo...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  41. 🟠 CVE-2026-89695 - High (7.5)

    In the Linux kernel, the following vulnerability has been resolved:

    nfsd: cap decoded POSIX ACL count to bound sort cost

    nfsd4_decode_posixacl() reads a u32 entry count off the wire and passes
    it straight to posix_acl_alloc() and sort_pacl_range...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  42. 🟠 CVE-2026-89692 - High (7.5)

    In the Linux kernel, the following vulnerability has been resolved:

    nfsd: clear CALLBACK_RUNNING on failed delegation recall queue

    nfsd_break_one_deleg() sets NFSD4_CALLBACK_RUNNING via test_and_set_bit
    at entry to serialize recall work, then ca...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  43. 🟠 CVE-2026-89690 - High (7.8)

    In the Linux kernel, the following vulnerability has been resolved:

    nfsd: defer vfree of compound ops to fix rpc_status UAF

    The rpc_status netlink dumpit walks every in-flight svc_rqst under
    rcu_read_lock and, for NFSv4 requests, reads opnums ou...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  44. 🟠 CVE-2026-89706 - High (7.5)

    In the Linux kernel, the following vulnerability has been resolved:

    nfsd: Reset write verifier when async COPY writeback fails

    Async COPY captures nn->writeverf at request time and reports it to
    the client via CB_OFFLOAD after the worker kthread...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  45. 🟠 CVE-2026-89704 - High (7.5)

    In the Linux kernel, the following vulnerability has been resolved:

    nfsd: sample writeback error cursor before async COPY loop

    _nfsd_copy_file_range() samples dst->f_wb_err into "since"
    after the copy loop, then uses it to detect writeback error...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  46. 🟠 CVE-2026-89736 - High (7.8)

    In the Linux kernel, the following vulnerability has been resolved:

    usb: gadget: u_audio: Fix use-after-free on sound card disconnect

    g_audio_cleanup() invokes snd_card_free_when_closed() to initiate sound
    card teardown and immediately frees the...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  47. 🟠 CVE-2026-89750 - High (7.8)

    In the Linux kernel, the following vulnerability has been resolved:

    tracing/user_events: Clear copied tracing state before fork duplication

    dup_task_struct() copies user_event_mm from the parent into the child,
    without grabbing a reference to it...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  48. 🟠 CVE-2026-89748 - High (7.8)

    In the Linux kernel, the following vulnerability has been resolved:

    tracing: Fix retry exhaustion in simple ring buffer reader swap

    simple_ring_buffer_swap_reader_page() starts with retry set to 8 and
    post-decrements it only after a failed link ...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  49. 🟠 CVE-2026-89747 - High (7.8)

    In the Linux kernel, the following vulnerability has been resolved:

    tracing: Fix use-after-free in trace_pipe read on sub-buffer order change

    Writing to buffer_subbuf_size_kb calls ring_buffer_subbuf_order_set(),
    which frees every sub-buffer of ...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

  50. 🟠 CVE-2026-89746 - High (7.8)

    In the Linux kernel, the following vulnerability has been resolved:

    tracing: Fix use-after-free with same-name named triggers

    When two hist triggers on different events are registered with the same
    name=, the second one reuses the first as named...

    πŸ”— thehackerwire.com/vulnerabilit

    #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack