๐จ CVE-2025-30650
A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root.
This issue affects systems running Junos OS using Linux-based line cards. Affected line cards include:
* MPC7, MPC8, MPC9, MPC10, MPC11
* LC2101, LC2103
* LC480, LC4800, LC9600
* MX304 (built-in FPC)
* MX-SPC3
* SRX5K-SPC3
* EX9200-40XS
* FPC3-PTX-U2, FPC3-PTX-U3
* FPC3-SFF-PTX
* LC1101, LC1102, LC1104, LC1105
This issue affects Junos OS:
* all versions before 22.4R3-S8,
* from 23.2 before 23.2R2-S6,
* from 23.4 before 23.4R2-S6,
* from 24.2 before 24.2R2-S3,
* from 24.4 before 24.4R2,
* from 25.2 before 25.2R2.
๐@cveNotify
A Missing Authentication for Critical Function vulnerability in command processing of Juniper Networks Junos OS allows a privileged local attacker to gain access to Linux-based line cards as root.
This issue affects systems running Junos OS using Linux-based line cards. Affected line cards include:
* MPC7, MPC8, MPC9, MPC10, MPC11
* LC2101, LC2103
* LC480, LC4800, LC9600
* MX304 (built-in FPC)
* MX-SPC3
* SRX5K-SPC3
* EX9200-40XS
* FPC3-PTX-U2, FPC3-PTX-U3
* FPC3-SFF-PTX
* LC1101, LC1102, LC1104, LC1105
This issue affects Junos OS:
* all versions before 22.4R3-S8,
* from 23.2 before 23.2R2-S6,
* from 23.4 before 23.4R2-S6,
* from 24.2 before 24.2R2-S3,
* from 24.4 before 24.4R2,
* from 25.2 before 25.2R2.
๐@cveNotify
GitHub
Juniper Junos - Privileged local user can gain access to a Linux-based FPC as root (CVE-2025-30650)
# Overview
A local attacker with high privileges (`shell` and `maintenance`) is able to escalate to root without the use of the root password.
# Details
A local attacker with very little p...
A local attacker with high privileges (`shell` and `maintenance`) is able to escalate to root without the use of the root password.
# Details
A local attacker with very little p...
๐จ CVE-2025-50644
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of user input in the qj.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of user input in the qj.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50645
A vulnerability has been discovered in D-Link DI-8003 16.07.26A1, which can lead to a buffer overflow when the s parameter in the pppoe_list_opt.asp endpoint is manipulated. By sending a crafted request with an excessively large value for the s parameter, an attacker can trigger a buffer overflow condition.
๐@cveNotify
A vulnerability has been discovered in D-Link DI-8003 16.07.26A1, which can lead to a buffer overflow when the s parameter in the pppoe_list_opt.asp endpoint is manipulated. By sending a crafted request with an excessively large value for the s parameter, an attacker can trigger a buffer overflow condition.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50646
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to insufficient input validation on the name parameter in the /qos_type_asp.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to insufficient input validation on the name parameter in the /qos_type_asp.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50647
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1, specifically in the handling of the wans parameter in the qos.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1, specifically in the handling of the wans parameter in the qos.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50648
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate input validation in the /tggl.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate input validation in the /tggl.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50649
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper input validation in the vlan_name parameter in the /shut_set.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper input validation in the vlan_name parameter in the /shut_set.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50650
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate validation of input size in the routes_static parameter in the /router.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to inadequate validation of input size in the routes_static parameter in the /router.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50652
An issue in D-Link DI-8003 16.07.26A1 related to improper handling of the id parameter in the /saveparm_usb.asp endpoint.
๐@cveNotify
An issue in D-Link DI-8003 16.07.26A1 related to improper handling of the id parameter in the /saveparm_usb.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50653
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name and mem parameters in the /time_group.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name and mem parameters in the /time_group.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50654
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of the id parameter in the /thd_member.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper validation of the id parameter in the /thd_member.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50655
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /thd_group.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /thd_group.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50657
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the pid parameter in the /trace.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the pid parameter in the /trace.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50659
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the custom_error parameter in the /user.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the custom_error parameter in the /user.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50660
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_member.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_member.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50662
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_group.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /url_group.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50663
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /usb_paswd.asp endpoint.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of the name parameter in the /usb_paswd.asp endpoint.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50664
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /user_group.asp endpoint. The attacker can exploit this vulnerability by sending a crafted HTTP GET request with parameters name, mem, pri, and attr.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of parameters in the /user_group.asp endpoint. The attacker can exploit this vulnerability by sending a crafted HTTP GET request with parameters name, mem, pri, and attr.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50665
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of input parameters in the /web_keyword.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request via the name, en, time, mem_gb2312, and mem_utf8 parameters.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of input parameters in the /web_keyword.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request via the name, en, time, mem_gb2312, and mem_utf8 parameters.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2025-50666
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /web_post.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in parameters such as name, en, user_id, log, and time.
๐@cveNotify
A buffer overflow vulnerability exists in D-Link DI-8003 16.07.26A1 due to improper handling of multiple parameters in the /web_post.asp endpoint. An attacker can exploit this vulnerability by sending a crafted HTTP GET request in parameters such as name, en, user_id, log, and time.
๐@cveNotify
GitHub
iot-vulnerability-collection/README.md at main ยท xiaotea/iot-vulnerability-collection
A collection of publicly disclosed IoT and router vulnerabilities with assigned CVE IDs. - xiaotea/iot-vulnerability-collection
๐จ CVE-2026-27308
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of this issue does not require user interaction.
๐@cveNotify
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. A high-privileged attacker could exploit this vulnerability and exhaust system resources, reducing application speed. Exploitation of this issue does not require user interaction.
๐@cveNotify
Adobe
Adobe Security Bulletin
Security updates available for Adobe ColdFusion | APSB26-38