#tenda — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #tenda, aggregated by home.social.
-
🟠 CVE-2026-85691 - High (7.5)
MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers can supply internal service URLs or metadata endpoints without authenticat...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85691/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85699 - High (7.5)
jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. Attackers can craft a public URL that redirects to internal network a...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85699/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85696 - Critical (9.8)
SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shell metacharacters in the fi...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85696/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-62928 - Critical (9.8)
XING CPTrans-ME-X contains an OS Command Injection (CWE-78). Unauthenticated OS command may be injected.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-62928/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85094 - High (8.8)
The Canva Android App before 2.376.0 did not restrict the headers returned to an external origin running in a privileged WebView. A threat actor with control of the WebView could access a user’s session.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85094/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85085 - Critical (9.6)
The Canva Android App before 2.376.0 allowed an external origin to be loaded in a privileged WebView. A threat actor who controls the page loaded by the user is able to communicate with Canva using the user’s session.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85085/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85506 - Critical (9.8)
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer overflow in _get_dell_system_info_idrac_info in ipmi-oem/ipmi-oem-dell.c (idrac-info subcommand to dell get-system-info).
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85506/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85505 - High (7.5)
ipmi-oem in FreeIPMI before 1.6.19 has a stack-based buffer over-read in ipmi_oem_fujitsu_get_sel_entry_long_text in ipmi-oem/ipmi-oem-fujitsu.c when a BMC provides a short response, a different vulnerability than CVE-2026-50031 (which has differe...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85505/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85504 - Critical (9.8)
FreeIPMI before 1.6.19 has a stack-based buffer overflow in _ipmi_sel_oem_fujitsu_get_sel_entry_long_text in libfreeipmi/sel/ipmi-sel-string-fujitsu-irmc-common.c via malformed Fujitsu SEL long-text responses.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85504/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85147 - High (7.5)
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain a specific password from the source code, which can be used to retrieve the AES encryption key used for c...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85147/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85146 - Critical (9.8)
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SSH service account credentials and passwords for the SmartIT Agent directly from the application sou...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85146/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85148 - Critical (9.8)
SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed password to remotely access user hosts.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85148/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85455 - High (8.2)
MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOOSDB port and send a crafted...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85455/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85452 - High (8.8)
MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validation. Attackers can supply ar...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85452/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85450 - High (7.5)
MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless header data to exhaust server th...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85450/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-64200 - High (7.8)
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a past the end of an allocated heap buffer during string conversion. Successful exploitation requires an attacker...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64200/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-64199 - High (7.8)
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read outside the bounds of an allocated data structure. Successful exploitation requires an attacker to get a user to ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64199/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-64198 - High (7.8)
There is an out-of-bounds read vulnerability in DASYLab due to improper validation of user-supplied data. This results in a read a few bytes past the end of an allocated heap buffer during file handling. Successful exploitation requires an at...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64198/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-64197 - High (7.8)
There is an out-of-bounds write vulnerability in DASYLab due to improper validation of user-supplied data, resulting in a write past the end of an allocated data structure. Successful exploitation requires an attacker to get a user to open a spec...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-64197/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85224 - Critical (9.1)
A vulnerability was determined in D-Link DNS-320 ShareCenter 2.06B01. This affects an unknown part of the file /cgi/file_sharing.cgi of the component File Sharing. Executing a manipulation of the argument fileurl can lead to os command injection. ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85224/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85223 - Critical (9.9)
A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval results ...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85223/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85391 - Critical (9.8)
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user ID...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85391 - Critical (9.8)
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user ID...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85391 - Critical (9.8)
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user ID...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85391 - Critical (9.8)
Peppermint through 0.5.5 contains a hardcoded JWT signing secret in docker-compose.yml that allows unauthenticated attackers to forge session tokens for any account. Attackers can use the published secret to mint valid tokens for arbitrary user ID...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85391/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85388 - High (8.1)
Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85388/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85388 - High (8.1)
Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85388/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85388 - High (8.1)
Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85388/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85388 - High (8.1)
Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL expressions into ORDER BY clauses. Attackers can use time-based and boolea...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85388/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85028 - High (7.8)
Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85028/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85028 - High (7.8)
Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85028/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85028 - High (7.8)
Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85028/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85028 - High (7.8)
Creation of a temporary file in a directory with insecure permissions in the FPGA management tool installation component in AWS FPGA Development Kit (aws-fpga) before 2.3.4 might allow local users to execute arbitrary code with root privileges via...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85028/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85396 - High (7.5)
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like .....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85396/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85396 - High (7.5)
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like .....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85396/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85396 - High (7.5)
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like .....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85396/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85396 - High (7.5)
rubyzip versions before 3.4.0 contain a path traversal vulnerability in Zip::Entry#extract that fails to properly validate extraction paths using prefix comparison without trailing separators. Attackers can craft archive entries with names like .....
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85396/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85394 - Critical (9.1)
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verific...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85394/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85394 - Critical (9.1)
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verific...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85394/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85394 - Critical (9.1)
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verific...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85394/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-85394 - Critical (9.1)
python-jose through 3.5.0 fails to properly validate asymmetric keys in HMAC initialization, accepting DER-encoded public keys that lack PEM armor or SSH prefixes. Attackers holding the service's public key can forge HS256 tokens that pass verific...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85394/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85393 - High (7.5)
node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85393/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85393 - High (7.5)
node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85393/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85393 - High (7.5)
node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85393/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85393 - High (7.5)
node-forge through 1.4.0 fails to validate element count in nested DigestAlgorithm sequences during RSA PKCS#1 v1.5 signature verification. Attackers can embed garbage bytes inside the DigestAlgorithm sequence to forge valid signatures for arbitra...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85393/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🔴 CVE-2026-58400 - Critical (9.1)
GeoNetwork is a catalog application to manage spatially referenced resources. Prior to versions 4.4.12 and 4.2.17, the Saxon XSLT processor used to render formatters is configured without secure processing (`FEATURE_SECURE_PROCESSING`) and without...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-58400/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-83959 - High (7.8)
Substance3D - Sampler is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-83959/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
🟠 CVE-2026-85012 - High (8)
Improper neutralization of special elements used in an OS command (CWE-78) in the blueprint resynthesis framework in Amazon Web Services codecatalyst-blueprints before 0.3.156 might allow a user with permission to commit to a repository in the pro...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85012/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack
-
CVE Alert: CVE-2026-85110 - Tenda - HG10 - https://www.redpacketsecurity.com/cve-alert-cve-2026-85110-tenda-hg10/
#OSINT #ThreatIntel #CyberSecurity #cve-2026-85110 #tenda #hg10
-
🔴 CVE-2026-85154 - Critical (9.8)
WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_...
🔗 https://www.thehackerwire.com/vulnerability/CVE-2026-85154/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack