#Firmware
All CosmicBytez Labs articles tagged #Firmware, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-36433: Actions Semiconductor Media Player Utilities RCE
A physically-proximate attacker can execute arbitrary code via Production.dll and RdiskUpgrade.exe in Actions Semiconductor's Media Player Utilities v4.46.
- Security
D-Link DWR-M961 Command Injection via FOTA Upgrade Interface (Quectel)
A command injection vulnerability in D-Link DWR-M961 routers (hardware C1) allows remote attackers to execute arbitrary OS commands via the fota_url...
- Security
D-Link DWR-M961 Command Injection via FOTA Upgrade Interface (Fibocom)
A command injection vulnerability in D-Link DWR-M961 routers (hardware C1) allows remote attackers to execute arbitrary OS commands via the fota_url...
- Security
MSI Radix AXE6600 Critical Command Injection in WPS Interface (CVE-2026-71983)
A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's wps.cgi interface allows remote attackers to execute arbitrary...
- Security
MSI Radix AXE6600 Critical Command Injection in URL Filter Function (CVE-2026-71984)
A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's urlfilter function allows remote attackers to execute arbitrary...
- Security
MSI Radix AXE6600 Critical Command Injection in Access Control Function (CVE-2026-71985)
A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's accesscontrol function enables remote attackers to execute arbitrary...
- Security
MSI Radix AXE6600 Critical Command Injection in DMZ Function (CVE-2026-71986)
A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's DMZ function allows remote attackers to execute arbitrary commands...
- News
Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes
A firmware flaw introduced in Coldcard's March 2021 4.0.0 release caused devices to skip hardware random number generation and fall back to predictable...
- News
CubePilot Drone Software Dev Hit by DNS Hijacking to Intercept Traffic
Australian UAV flight controller maker CubePilot had its domain seized by attackers on July 24, who obtained valid TLS certificates and potentially...
- News
Six U-Boot Flaws Could Enable Stealthy Firmware Attacks on Embedded Devices
Researchers have discovered six vulnerabilities in the widely deployed U-Boot bootloader that could allow attackers to execute malicious code at boot...
- News
Flipper Zero Firmware Development Continues With Community Help
Flipper Devices is downsizing its internal development team but confirms that Flipper Zero firmware development will continue, with greater reliance on...
- Security
CVE-2026-50211: Leftover Engineering Diagnostics Grant Malicious Apps NVRAM Write Access
A critical CVSS 9.8 vulnerability exposes factory-level diagnostic interfaces left in retail firmware builds, allowing malicious applications to gain write…
- Security
CVE-2026-6274: Critical Authentication Bypass in DTS Redline WR3200 Router
A critical authentication bypass vulnerability in the DTS Electronics Redline WR3200 router allows unauthenticated attackers to access functionality protected…
- Security
CVE-2026-35075: Hardcoded Default Password in Firmware Enables Full Device Takeover (CVSS 9.8)
A CVSS 9.8 critical vulnerability allows unauthenticated remote attackers to recover a default hardcoded password from a firmware image, granting full…
- News
Eclypsium Raises $25 Million to Expand Device Supply Chain
Portland-based Eclypsium has secured $25 million in strategic funding led by PEAK6 Strategic Capital, bringing its total raised to $110 million. The...