Cybersecurity & Regolamentazione UE

News & Sicurezza

Aggiornamenti da ENISA, NVD e le principali fonti di cybersecurity europee. Tutto quello che un Responsabile Tecnico deve sapere.

38015 risultati

VulnerabilitàCritica
CVE-2026-7243 (CVSS 9.8)

A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument maxRtrAdvInterval leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

NVD (NIST)28 apr 2026
VulnerabilitàCritica
CVE-2026-7242 (CVSS 9.8)

A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnClientCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument enabled can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

NVD (NIST)28 apr 2026
VulnerabilitàCritica
CVE-2026-7241 (CVSS 9.8)

A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument wifiOff results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

NVD (NIST)28 apr 2026
VulnerabilitàAlta
CVE-2026-7242 - Totolink A8000RU CGI cstecgi.cgi setOpenVpnClientCfg os command injection

CVE ID :CVE-2026-7242 Published : April 28, 2026, 9:16 a.m. | 3 hours ago Description :A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setOpenVpnClientCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Executing a manipulation of the argument enabled can lead to os command injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Severity: 10.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-7241 - Totolink A8000RU CGI cstecgi.cgi setWiFiBasicCfg os command injection

CVE ID :CVE-2026-7241 Published : April 28, 2026, 9:16 a.m. | 3 hours ago Description :A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setWiFiBasicCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. Performing a manipulation of the argument wifiOff results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Severity: 10.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-7243 - Totolink A8000RU CGI cstecgi.cgi setRadvdCfg os command injection

CVE ID :CVE-2026-7243 Published : April 28, 2026, 9:16 a.m. | 3 hours ago Description :A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The affected element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument maxRtrAdvInterval leads to os command injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. Severity: 10.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-7244 - Totolink A8000RU CGI cstecgi.cgi setWiFiEasyGuestCfg os command injection

CVE ID :CVE-2026-7244 Published : April 28, 2026, 9:16 a.m. | 3 hours ago Description :A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is the function setWiFiEasyGuestCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument merge results in os command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks. Severity: 10.0 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-40980 - Spring AI Memory Allocation Denial of Service (DoS)

CVE ID :CVE-2026-40980 Published : April 28, 2026, 9:16 a.m. | 3 hours ago Description :In Spring AI, a malicious PDF file can be crafted that triggers the allocation of unreasonable amounts of memory when handled by `ForkPDFLayoutTextStripper`. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5) Severity: 6.5 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2025-10539 - Improper TLS Certificate Validation RCE via Malicious Update in DeskTime Time Tracking App

CVE ID :CVE-2025-10539 Published : April 28, 2026, 9:16 a.m. | 1 hour ago Description :Due to improper TLS certificate validation in the DeskTime Time Tracking App before version 1.3.674, attackers who can position themselves in the network path between the client and the DeskTime update servers can return a malicious executable in response to an update request. This allows the attacker to achieve user-level remote code execution on the affected client. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-40979 - Spring AI ONNX Model Exposure Vulnerability

CVE ID :CVE-2026-40979 Published : April 28, 2026, 9:16 a.m. | 3 hours ago Description :In Spring AI, having access to a shared environment can expose the ONNX model used by the application. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5) Severity: 6.1 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2026-40978 - Spring AI CosmosDBVectorStore SQL Injection

CVE ID :CVE-2026-40978 Published : April 28, 2026, 9:16 a.m. | 3 hours ago Description :SQL injection vulnerability in Spring AI's `CosmosDBVectorStore` allows attackers to execute arbitrary SQL queries via crafted document IDs. Affected versions: Spring AI: 1.0.0 - 1.0.5 (fixed in 1.0.6), 1.1.0 - 1.1.4 (fixed in 1.1.5) Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026
VulnerabilitàAlta
CVE-2025-48431 - Apache Thrift: Specially crafted input can crash a c_glib Thrift server with invalid pointer error.

CVE ID :CVE-2025-48431 Published : April 28, 2026, 10:16 a.m. | 2 hours ago Description :Mismatched Memory Management Routines vulnerability in Apache Thrift c_glib language bindings. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue. Description: Specially crafted requests can crash an c_glib-based Thrift server with a clean but fatal "free(): invalid pointer" error message. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVEfeed CVE28 apr 2026

Pagina 2035 di 3168

Resta aggiornato sulla cybersecurity

Iscriviti a CodersRegistry per ricevere gli aggiornamenti più importanti su regolamentazione EU e vulnerabilità critiche.