Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

33693 risultati

VulnerabilitàCritica
CVE-2026-71958 (CVSS 9.8)

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash.

NVD (NIST)08 ago 2026
VulnerabilitàCritica
CVE-2026-71957 (CVSS 9.8)

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash.

NVD (NIST)08 ago 2026
VulnerabilitàCritica
CVE-2026-71956 (CVSS 9.8)

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command execution with root privileges.

NVD (NIST)08 ago 2026
VulnerabilitàAlta
CVE-2026-71956 - D-Link DWR-M961 Command Injection via app.cgi

CVE ID :CVE-2026-71956 Published : Aug. 8, 2026, 6:16 p.m. | 8 hours, 10 minutes ago Description :D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command execution with root privileges. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàAlta
CVE-2026-71958 - D-Link DWR-M961 Buffer Overflow via quicksetup.cgi

CVE ID :CVE-2026-71958 Published : Aug. 8, 2026, 6:16 p.m. | 10 hours, 10 minutes ago Description :D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàAlta
CVE-2026-71957 - D-Link DWR-M961 Buffer Overflow via app.cgi

CVE ID :CVE-2026-71957 Published : Aug. 8, 2026, 6:16 p.m. | 10 hours, 10 minutes ago Description :D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàCritica
CVE-2026-71955 (CVSS 9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin field, resulting in command execution with root privileges.

NVD (NIST)08 ago 2026
VulnerabilitàCritica
CVE-2026-71954 (CVSS 9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges.

NVD (NIST)08 ago 2026
VulnerabilitàAlta
CVE-2026-71954 - D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetup

CVE ID :CVE-2026-71954 Published : Aug. 8, 2026, 5:16 p.m. | 9 hours, 10 minutes ago Description :D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàAlta
CVE-2026-71955 - D-Link DWR-M961 Command Injection via /boafrm/formWsc

CVE ID :CVE-2026-71955 Published : Aug. 8, 2026, 5:16 p.m. | 9 hours, 10 minutes ago Description :D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin, targetAPSsid, peerPin, and peerRptPin fields, resulting in command execution with root privileges. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàCritica
CVE-2026-71953 (CVSS 9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges.

NVD (NIST)08 ago 2026
VulnerabilitàCritica
CVE-2026-71952 (CVSS 9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in command execution with root privileges.

NVD (NIST)08 ago 2026

Pagina 150 di 2808

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.