CVE tracker
394 subscribers
5.76K links
News monitoring: @irnewsagency

Main channel: @orgsecuritygate

Site: SecurityGate.org
Download Telegram
CVE-2026-82357 - RT-Labs AB C-Open CANopen NULL pointer dereference

CVE ID :CVE-2026-82357
Published : Oct. 1, 2026, 8:17 p.m. | 1 hour, 22 minutes ago
Description :RT-Labs AB C-Open CANopen contains a NULL pointer dereference if the LSS protocol is used to configure the device. An object defined by the user application may not have all required subindexes for object 0x1018. An unauthenticated, remote attacker with access to the CAN bus, through a compromised node for instance, can initiate the LSS protocol on a device with a misconfigured identity object and potentially crash the device. Fixed in 1.1.1.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-82358 - RT-Labs AB C-Open CANopen SDO Server Write Protection Bypass

CVE ID :CVE-2026-82358
Published : Oct. 1, 2026, 8:17 p.m. | 1 hour, 22 minutes ago
Description :RT-Labs AB C-Open CANopen contains a write protection bypass in the SDO (Service Data Object) server implementation 'src/co_sdo_server.c' that fails to properly validate write permissions when processing download-segment frames. An unauthenticated attacker on the CAN bus can initiate an SDO upload for a read-only Object Dictionary (OD) entry, which sets a data pointer to the read-only object, then send download-segment frames to write to that memory location. The download-segment handler does not verify that a download session is active, allowing any CANopen node to overwrite read-only OD entries using two SDO frames. Note that CANopen protocol operates over CAN bus and does not provide built-in authentication mechanisms. Fixed in 1.1.1.
Severity: 7.1 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-93832 - Motorola System Application Unauthorized Permission Revocation Vulnerability

CVE ID :CVE-2026-93832
Published : Oct. 1, 2026, 8:17 p.m. | 1 hour, 22 minutes ago
Description :A component of one of the Motorola system applications was exported without permission, allowing for the revocation of runtime permissions from other apps.
Severity: 4.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104002 - Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python)

CVE ID :CVE-2026-104002
Published : Oct. 1, 2026, 9:05 p.m. | 33 minutes ago
Description :A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask.  To remediate this issue, users should upgrade to version 3.35.0.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-71452 - Johnson Controls EasyIO FS32 OS Command Injection

CVE ID :CVE-2026-71452
Published : Oct. 1, 2026, 9:06 p.m. | 33 minutes ago
Description :- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63.
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104051 - PictShare < 3.7.1 Sensitive Information Disclosure via info API

CVE ID :CVE-2026-104051
Published : Oct. 1, 2026, 9:08 p.m. | 31 minutes ago
Description :PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint which returns the complete raw metadata object without a field whitelist. Attackers can use the publicly visible file hash to retrieve the delete_code via the info API and then invoke the delete API to permanently delete arbitrary files, while also exposing uploader IP, User Agent, remote port, and SHA-1 hash, resulting in loss of content integrity, availability, and uploader privacy.
Severity: 8.2 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-71453 - Johnson Controls EasyIO FS32 Path Traversal Vulnerability

CVE ID :CVE-2026-71453
Published : Oct. 1, 2026, 9:10 p.m. | 29 minutes ago
Description :- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO FS32: before 3.0b63.
Severity: 5.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-71454 - CAPEC-63 Cross-Site Scripting Vulnerability

CVE ID :CVE-2026-71454
Published : Oct. 1, 2026, 9:13 p.m. | 26 minutes ago
Description :Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in CWE-79 - Cross-site Scripting CAPEC-63 allows Cross-Site Scripting (XSS). This issue affects CAPEC-63: before 3.0b63.
Severity: 5.8 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-71448 - Johnson Controls EasyIO FS32 Insecure Default Initialization of Resource Vulnerability

CVE ID :CVE-2026-71448
Published : Oct. 1, 2026, 9:15 p.m. | 24 minutes ago
Description :: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: before 3.0b63.
Severity: 5.6 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-71449 - Johnson Controls EasyIO FS32 Hard-coded Cryptographic Key Vulnerability

CVE ID :CVE-2026-71449
Published : Oct. 1, 2026, 9:16 p.m. | 22 minutes ago
Description :: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102370 - Physical UART Access Leading to an Unauthenticated Root Shell in TP-Link Kasa EC70 and EC71

CVE ID :CVE-2026-102370
Published : Oct. 1, 2026, 9:17 p.m. | 22 minutes ago
Description :Kasa EC70 v4 and EC71 v4 do not logically disable the production debug interface at the firmware or chip level and do not lock the bootloader.  Although the debug traces are physically severed during manufacturing, an attacker with physical access can restore the connection, interrupt the boot process, and manipulate boot parameters to enter a non-standard initialization path that exposes an unauthenticated root shell during startup. Successful exploitation may allow an attacker with physical access to obtain root-level command access during device startup, resulting in loss of confidentiality, integrity, and availability for the affected device. Exploitation requires device disassembly, restoration of the severed debug connection, and manipulation of the boot process.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-102514 - Out-of-bounds write in PeaZip PEA extractor allows code execution via a crafted .pea archive

CVE ID :CVE-2026-102514
Published : Oct. 1, 2026, 9:17 p.m. | 22 minutes ago
Description :Out-of-bounds Write (CWE-787) in the PEA archive extraction routine (pea.pas, unpea_procedure) of the first-party pea component in PeaZip 11.2.0 and earlier allows an attacker who convinces a victim to open or extract a crafted .pea archive to execute arbitrary code as the user running PeaZip. While decompressing a PCOMPRESS1 stream, the 32-bit compressed-block-size field of the first block (compsize) is read directly from the archive and used without validation as the length of a blockread into the fixed-size global buffers wbuf1/wbuf2 (1,114,112 bytes) and as the bound of the subsequent copy loop. The existing check "compsize > WBUFSIZE" is applied only to the size of each following block, so the first block escapes it; the same unvalidated value is also used to index wbuf1[compsize], an out-of-bounds read at an attacker-chosen offset. The copy loop additionally copies the requested length instead of the number of bytes actually read, and terminates on equality rather than on an upper bound. Because the project is built without range checking and no archive password, integrity tag or non-default configuration is required, the overflow overwrites adjacent global data; code execution was demonstrated by two independent researchers against the official Linux x86-64 and Windows x64 builds, and the denial-of-service and memory-corruption primitive is cross-platform (Windows, macOS, Linux, BSD).
Severity: 8.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104020 - Uncontrolled recursion in the Ion reader in Amazon Ion Python

CVE ID :CVE-2026-104020
Published : Oct. 1, 2026, 9:17 p.m. | 22 minutes ago
Description :Uncontrolled recursion in the Ion reader in Amazon Ion Python before 0.15.0 might allow a remote unauthenticated actor to crash the application using the library, resulting in a denial of service, via a crafted, deeply nested Ion value. To remediate this issue, users should upgrade to version 0.15.0 or later.
Severity: 8.7 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104181 - Filament: Multi-factor authentication (app) management actions do not require password reauthentication

CVE ID :CVE-2026-104181
Published : Oct. 1, 2026, 9:17 p.m. | 22 minutes ago
Description :Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.13.3 and 5.8.3, app-based multi-factor authentication management actions do not consistently require confirmation of the current password. An attacker with access to an authenticated user session can set up app-based MFA and obtain recovery codes, or disable app-based MFA and regenerate recovery codes by supplying an existing app code or recovery code, without knowing the account password. Email-based MFA is not affected, and the issue does not independently permit an unauthenticated sign-in, but changing the app-MFA configuration may lock the legitimate user out. This issue is fixed in versions 4.13.3 and 5.8.3.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104182 - stream-json: JSONC parser and verifier re-scan the whole accumulated comment on every input chunk

CVE ID :CVE-2026-104182
Published : Oct. 1, 2026, 9:17 p.m. | 22 minutes ago
Description :stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, the JSONC parser at stream-json/jsonc/parser.js and verifier at stream-json/jsonc/verifier.js restart comment-terminator scanning from the opening slash whenever a block or line comment spans an input chunk, while retaining the accumulated comment buffer. Delivering a large valid comment across many small chunks therefore causes quadratic CPU work and can stall the Node.js event loop. The maintainer characterizes the attack vector as local because the documented JSONC input is locally owned or user-controlled configuration, rather than input intended for the open internet. This JSONC-only scope does not include the plain JSON parser, which advances through and discards consumed string and number data. This issue is fixed in version 3.6.0.
Severity: 6.2 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-104183 - stream-json: Prototype pollution: Assembler writes this.current[this.key] on plain objects

CVE ID :CVE-2026-104183
Published : Oct. 1, 2026, 9:17 p.m. | 22 minutes ago
Description :stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.6.0, Assembler materializes object properties with plain assignment, so an input key named __proto__ invokes the inherited setter and causes parsed object prototype replacement instead of creating an own data property. Applications that make authorization or feature decisions from inherited values can therefore consume attacker-controlled properties, and a null prototype can disrupt code that expects Object.prototype methods. The researcher treats parsing untrusted JSON as part of the project contract, while the maintainer states that documented inputs are locally owned dumps, exports, or logs and characterizes the attack vector as local. The global Object.prototype is not polluted. This issue is fixed in version 3.6.0.
Severity: 5.1 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-27874 - Johnson Controls EasyIO FS32 Hard-coded Credentials Vulnerability

CVE ID :CVE-2026-27874
Published : Oct. 1, 2026, 9:17 p.m. | 22 minutes ago
Description :: Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before 3.0b63.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-55393 - Local File Inclusion in Teledyne FLIR Robots running Aware2

CVE ID :CVE-2026-55393
Published : Oct. 1, 2026, 9:17 p.m. | 22 minutes ago
Description :Unvalidated pathnames in the web interface in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to read configuration and security parameters on Teledyne FLIR PackBot and FirstLook robots running this software via path traversal.
Severity: 10.0 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-55394 - Unencrypted 802.11 Network in Teledyne FLIR Robots running Aware2

CVE ID :CVE-2026-55394
Published : Oct. 1, 2026, 9:17 p.m. | 22 minutes ago
Description :Unencrypted traffic in the 802.11 network of Teledyne FLIR Aware2 versions through 6.9.0.2 allows adjacent unauthenticated attackers to intercept, hijack, or modify session traffic against Teledyne FLIR PackBot robots running this software via sniffing or hijacking network traffic.
Severity: 5.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-55395 - Hardcoded Passwords in Teledyne FLIR Robots running Aware2

CVE ID :CVE-2026-55395
Published : Oct. 1, 2026, 9:17 p.m. | 22 minutes ago
Description :Hardcoded passwords in the access control in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows remote unauthenticated attackers to access and reconfigure Teledyne FLIR PackBot and FirstLook robots running this software via reading the passwords from the firmware or documentation.
Severity: 9.4 | CRITICAL
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-55396 - Unencrypted UDP Control Traffic in Teledyne FLIR Robots running Aware2

CVE ID :CVE-2026-55396
Published : Oct. 1, 2026, 9:17 p.m. | 22 minutes ago
Description :Cleartext transmission without a cryptographic integrity check in operator control unit to robot UDP traffic in Teledyne FLIR Aware2 versions through 6.9.0.2 (PackBot) and 1.7.9 (FirstLook) allows adjacent unauthenticated attackers to intercept, hijack, or modify control traffic against Teledyne FLIR PackBot and FirstLook robots running this software via sniffing or hijacking network traffic.
Severity: 8.5 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...