πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
πŸ•΄ Mandiant Bolsters SaaS Platform With Integration of New Attack Surface Management Module πŸ•΄

New automated offering helps organizations gain comprehensive visibility across IT environments, continuously monitor for vulnerabilities, operationalize threat intelligence and manage risk.

πŸ“– Read

via "Dark Reading".
❌ Kronos Still Dragging Itself Back From Ransomware Hell ❌

And customers including Tesla, PepsiCo and NYC transit workers are filing lawsuits over the β€œreal pain in the rear end” of manual inputting, inaccurate wages & more.

πŸ“– Read

via "Threat Post".
β€Ό CVE-2021-45268 β€Ό

A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading a maliciously add-on with crafted PHP file.

πŸ“– Read

via "National Vulnerability Database".
πŸ•΄ Mac Malware-Dropping Adware Gets More Dangerous πŸ•΄

The authors of UpdateAgent have tweaked it yet again β€” for the fifth time in less than 18 months.

πŸ“– Read

via "Dark Reading".
β€Ό CVE-2022-24153 β€Ό

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formAddMacfilterRule. This vulnerability allows attackers to cause a Denial of Service (DoS) via the devName parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45989 β€Ό

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function guestWifiRuleRefresh. This vulnerability allows attackers to cause a Denial of Service (DoS) via the qosGuestUpstream and qosGuestDownstream parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45987 β€Ό

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a command injection vulnerability in the function formSetNetCheckTools. This vulnerability allows attackers to execute arbitrary commands via the hostName parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46230 β€Ό

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function upgrade_filter. This vulnerability allows attackers to execute arbitrary commands via the path and time parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24172 β€Ό

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formAddDhcpBindRule. This vulnerability allows attackers to cause a Denial of Service (DoS) via the addDhcpRules parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24148 β€Ό

Tenda AX3 v16.03.12.10_CN was discovered to contain a command injection vulnerability in the function mDMZSetCfg. This vulnerability allows attackers to execute arbitrary commands via the dmzIp parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45995 β€Ό

Tenda routers G1 and G3 v15.11.0.17(9502)_CN were discovered to contain a stack overflow in the function formSetStaticRoute. This vulnerability allows attackers to cause a Denial of Service (DoS) via the staticRouteNet, staticRouteMask, and staticRouteGateway parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24145 β€Ό

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formWifiBasicSet. This vulnerability allows attackers to cause a Denial of Service (DoS) via the security and security_5g parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24163 β€Ό

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the timeZone parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24147 β€Ό

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromAdvSetMacMtuWan. This vulnerability allows attackers to cause a Denial of Service (DoS) via the wanMTU, wanSpeed, cloneType, mac, and serviceName parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46452 β€Ό

D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetNetworkTomographySettings. This vulnerability allows attackers to execute arbitrary commands via the tomography_ping_address, tomography_ping_number, tomography_ping_size, tomography_ping_timeout, and tomography_ping_ttl parameters.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-45733 β€Ό

TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the parameter host_time.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46455 β€Ό

D-Link device D-Link DIR-823-Pro v1.0.2 was discovered to contain a command injection vulnerability in the function SetStationSettings. This vulnerability allows attackers to execute arbitrary commands via the station_access_enable parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24154 β€Ό

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetRebootTimer. This vulnerability allows attackers to cause a Denial of Service (DoS) via the rebootTime parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46229 β€Ό

D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function usb_paswd.asp. This vulnerability allows attackers to execute arbitrary commands via the name parameter.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-44880 β€Ό

D-Link devices DIR_878 DIR_878_FW1.30B08_Hotfix_02 and DIR_882 DIR_882_FW1.30B06_Hotfix_02 were discovered to contain a command injection vulnerability in the system function. This vulnerability allows attackers to execute arbitrary commands via a crafted HNAP1 POST request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-24146 β€Ό

Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function formSetQosBand. This vulnerability allows attackers to cause a Denial of Service (DoS) via the list parameter.

πŸ“– Read

via "National Vulnerability Database".