All CosmicBytez Labs articles tagged #Firmware, across news, security advisories, how-to guides, and projects.
A command injection vulnerability in D-Link DWR-M961 routers (hardware C1) allows remote attackers to execute arbitrary OS commands via the fota_url parameter in the Quectel FOTA upgrade interface.
A command injection vulnerability in D-Link DWR-M961 routers (hardware C1) allows remote attackers to execute arbitrary OS commands via the fota_url parameter in the Fibocom FOTA upgrade interface.
A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's wps.cgi interface allows remote attackers to execute arbitrary commands as root by injecting malicious input through unsanitized WPS PIN parameters.
A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's urlfilter function allows remote attackers to execute arbitrary commands as root, enabling full device takeover via the URL filtering management interface.
A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's accesscontrol function enables remote attackers to execute arbitrary commands as root, bypassing network access restrictions and achieving full device compromise.
A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's DMZ function allows remote attackers to execute arbitrary commands as root, completing a cluster of four critical command injection flaws in firmware v781521.
A firmware flaw introduced in Coldcard's March 2021 4.0.0 release caused devices to skip hardware random number generation and fall back to predictable software seeding. The result: 1,082.65 BTC drained from 1,196 addresses in 41 minutes on July 30.
Australian UAV flight controller maker CubePilot had its domain seized by attackers on July 24, who obtained valid TLS certificates and potentially poisoned firmware distribution channels — warning operators not to flash firmware downloaded during the incident window.
Researchers have discovered six vulnerabilities in the widely deployed U-Boot bootloader that could allow attackers to execute malicious code at boot...
Flipper Devices is downsizing its internal development team but confirms that Flipper Zero firmware development will continue, with greater reliance on...
A critical CVSS 9.8 vulnerability exposes factory-level diagnostic interfaces left in retail firmware builds, allowing malicious applications to gain write…
A critical authentication bypass vulnerability in the DTS Electronics Redline WR3200 router allows unauthenticated attackers to access functionality protected…
A CVSS 9.8 critical vulnerability allows unauthenticated remote attackers to recover a default hardcoded password from a firmware image, granting full…
Portland-based Eclypsium has secured $25 million in strategic funding led by PEAK6 Strategic Capital, bringing its total raised to $110 million. The...