Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2368+ Articles
158+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
14 articles

#Firmware

All CosmicBytez Labs articles tagged #Firmware, across news, security advisories, how-to guides, and projects.

  • SecurityAug 9, 2026

    D-Link DWR-M961 Command Injection via FOTA Upgrade Interface (Quectel)

    A command injection vulnerability in D-Link DWR-M961 routers (hardware C1) allows remote attackers to execute arbitrary OS commands via the fota_url parameter in the Quectel FOTA upgrade interface.

  • SecurityAug 9, 2026

    D-Link DWR-M961 Command Injection via FOTA Upgrade Interface (Fibocom)

    A command injection vulnerability in D-Link DWR-M961 routers (hardware C1) allows remote attackers to execute arbitrary OS commands via the fota_url parameter in the Fibocom FOTA upgrade interface.

  • SecurityAug 9, 2026

    MSI Radix AXE6600 Critical Command Injection in WPS Interface (CVE-2026-71983)

    A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's wps.cgi interface allows remote attackers to execute arbitrary commands as root by injecting malicious input through unsanitized WPS PIN parameters.

  • SecurityAug 9, 2026

    MSI Radix AXE6600 Critical Command Injection in URL Filter Function (CVE-2026-71984)

    A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's urlfilter function allows remote attackers to execute arbitrary commands as root, enabling full device takeover via the URL filtering management interface.

  • SecurityAug 9, 2026

    MSI Radix AXE6600 Critical Command Injection in Access Control Function (CVE-2026-71985)

    A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's accesscontrol function enables remote attackers to execute arbitrary commands as root, bypassing network access restrictions and achieving full device compromise.

  • SecurityAug 9, 2026

    MSI Radix AXE6600 Critical Command Injection in DMZ Function (CVE-2026-71986)

    A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's DMZ function allows remote attackers to execute arbitrary commands as root, completing a cluster of four critical command injection flaws in firmware v781521.

  • NewsAug 1, 2026

    Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

    A firmware flaw introduced in Coldcard's March 2021 4.0.0 release caused devices to skip hardware random number generation and fall back to predictable software seeding. The result: 1,082.65 BTC drained from 1,196 addresses in 41 minutes on July 30.

  • NewsJul 28, 2026

    CubePilot Drone Software Dev Hit by DNS Hijacking to Intercept Traffic

    Australian UAV flight controller maker CubePilot had its domain seized by attackers on July 24, who obtained valid TLS certificates and potentially poisoned firmware distribution channels — warning operators not to flash firmware downloaded during the incident window.

  • NewsJul 12, 2026

    Six U-Boot Flaws Could Enable Stealthy Firmware Attacks on Embedded Devices

    Researchers have discovered six vulnerabilities in the widely deployed U-Boot bootloader that could allow attackers to execute malicious code at boot...

  • NewsJul 5, 2026

    Flipper Zero Firmware Development Continues With Community Help

    Flipper Devices is downsizing its internal development team but confirms that Flipper Zero firmware development will continue, with greater reliance on...

  • SecurityJun 5, 2026

    CVE-2026-50211: Leftover Engineering Diagnostics Grant Malicious Apps NVRAM Write Access

    A critical CVSS 9.8 vulnerability exposes factory-level diagnostic interfaces left in retail firmware builds, allowing malicious applications to gain write…

  • SecurityJun 5, 2026

    CVE-2026-6274: Critical Authentication Bypass in DTS Redline WR3200 Router

    A critical authentication bypass vulnerability in the DTS Electronics Redline WR3200 router allows unauthenticated attackers to access functionality protected…

  • SecurityJun 3, 2026

    CVE-2026-35075: Hardcoded Default Password in Firmware Enables Full Device Takeover (CVSS 9.8)

    A CVSS 9.8 critical vulnerability allows unauthenticated remote attackers to recover a default hardcoded password from a firmware image, granting full…

  • NewsMar 20, 2026

    Eclypsium Raises $25 Million to Expand Device Supply Chain

    Portland-based Eclypsium has secured $25 million in strategic funding led by PEAK6 Strategic Capital, bringing its total raised to $110 million. The...