Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

33708 risultati

VulnerabilitàAlta
CVE-2026-71954 - D-Link DWR-M961 Command Injection via /boafrm/formL2tpv3ConfigSetup

CVE ID :CVE-2026-71954 Published : Aug. 8, 2026, 5:16 p.m. | 9 hours, 10 minutes ago Description :D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàCritica
CVE-2026-71953 (CVSS 9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges.

NVD (NIST)08 ago 2026
VulnerabilitàCritica
CVE-2026-71952 (CVSS 9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in command execution with root privileges.

NVD (NIST)08 ago 2026
VulnerabilitàCritica
CVE-2026-71951 (CVSS 9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_value field, resulting in command execution with root privileges.

NVD (NIST)08 ago 2026
VulnerabilitàCritica
CVE-2026-71950 (CVSS 9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the action_value field, resulting in command execution with root privileges.

NVD (NIST)08 ago 2026
VulnerabilitàCritica
CVE-2026-71949 (CVSS 9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdValue and selectMenuValue fields, resulting in command execution with root privileges.

NVD (NIST)08 ago 2026
VulnerabilitàCritica
CVE-2026-71948 (CVSS 9.8)

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges.

NVD (NIST)08 ago 2026
VulnerabilitàAlta
CVE-2026-71951 - D-Link DWR-M961 Command Injection via /boafrm/formIMEISetup

CVE ID :CVE-2026-71951 Published : Aug. 8, 2026, 5:16 p.m. | 9 hours, 10 minutes ago Description :D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_value field, resulting in command execution with root privileges. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàAlta
CVE-2026-71950 - D-Link DWR-M961 Command Injection via /boafrm/formSmsManage

CVE ID :CVE-2026-71950 Published : Aug. 8, 2026, 5:16 p.m. | 9 hours, 10 minutes ago Description :D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the action_value field, resulting in command execution with root privileges. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàAlta
CVE-2026-71953 - D-Link DWR-M961 Command Injection via /boafrm/formNtp

CVE ID :CVE-2026-71953 Published : Aug. 8, 2026, 5:16 p.m. | 9 hours, 10 minutes ago Description :D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàAlta
CVE-2026-71948 - D-Link DWR-M961 Command Injection via /boafrm/formDebugDiagnosticRun

CVE ID :CVE-2026-71948 Published : Aug. 8, 2026, 5:16 p.m. | 7 hours, 9 minutes ago Description :D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026
VulnerabilitàAlta
CVE-2026-71952 - D-Link DWR-M961 Command Injection via /boafrm/formPinManageSetup

CVE ID :CVE-2026-71952 Published : Aug. 8, 2026, 5:16 p.m. | 9 hours, 10 minutes ago Description :D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in command execution with root privileges. Severity: 9.8 | CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE08 ago 2026

Pagina 152 di 2809

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.