Latest CVE Feed
-
7.1
HIGHCVE-2025-35008
Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MMNAME command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization o... Read more
Affected Products :- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-35007
Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFRULE command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization o... Read more
Affected Products :- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-35006
Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFPORTFWD command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralizatio... Read more
Affected Products :- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-35005
Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFMAC command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of... Read more
Affected Products :- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2025-35004
Products that incorporate the Microhard BulletLTE-NA2 and IPn4Gii-NA2 are vulnerable to a post-authentication command injection issue in the AT+MFIP command that can lead to privilege escalation. This is an instance of CWE-88, "Improper Neutralization of ... Read more
Affected Products :- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
7.7
HIGHCVE-2025-32459
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the sync_time argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument I... Read more
Affected Products :- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
7.7
HIGHCVE-2025-32458
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_syslog_from_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('... Read more
Affected Products :- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
7.7
HIGHCVE-2025-32457
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the get_file_from_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Ar... Read more
Affected Products :- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
7.7
HIGHCVE-2025-32456
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the put_file_to_qtn argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argu... Read more
Affected Products :- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
7.7
HIGHCVE-2025-32455
The Quantenna Wi-Fi chipset ships with a local control script, router_command.sh (in the run_cmd argument), that is vulnerable to command injection. This is an instance of CWE-88, "Improper Neutralization of Argument Delimiters in a Command ('Argument Inj... Read more
Affected Products :- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
9.0
HIGHCVE-2025-5847
A vulnerability has been found in Tenda AC9 15.03.02.13 and classified as critical. Affected by this vulnerability is the function formSetSafeWanWebMan of the file /goform/SetRemoteWebCfg of the component HTTP POST Request Handler. The manipulation of the... Read more
- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Memory Corruption
-
5.5
MEDIUMCVE-2025-27563
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-27247
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-27242
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Denial of Service
-
6.1
MEDIUMCVE-2025-27131
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through improper input.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-26693
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Information Disclosure
-
5.5
MEDIUMCVE-2025-26691
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through get permission.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Authorization
-
5.5
MEDIUMCVE-2025-25217
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through NULL pointer dereference.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Denial of Service
-
5.5
MEDIUMCVE-2025-24493
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause information leak through race condition.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Race Condition
-
5.5
MEDIUMCVE-2025-23235
in OpenHarmony v5.0.3 and prior versions allow a local attacker cause DOS through out-of-bounds read.... Read more
Affected Products : openharmony- Published: Jun. 08, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Denial of Service