Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2614+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
22 articles

#IoT Security

All CosmicBytez Labs articles tagged #IoT Security, across news, security advisories, how-to guides, and projects.

  • SecurityAug 30, 2026

    Shinobi NVR: Hardcoded Child-Node Key Enables Unauthenticated Database Compromise (CVE-2026-82448)

    CVE-2026-82448 (CVSS 9.8): a hardcoded key in Shinobi's child-node service lets attackers run arbitrary SQL against user and camera data.

  • SecurityAug 30, 2026

    rust-iot-platform: Missing Auth Guards Expose the Entire User-Management API (CVE-2026-82452)

    CVE-2026-82452 (CVSS 9.8): rust-iot-platform's REST API lacks auth checks — anyone can create, edit, or delete accounts, no login required.

  • NewsAug 28, 2026

    Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE — One Starts Over Bluetooth

    Researcher discloses two root RCE chains in the Unitree G1 EDU robot; one is a wormable, unauthenticated Bluetooth exploit reaching root remotely.

  • SecurityAug 27, 2026

    CVE-2026-77533: UniFi Protect Command Injection via Improper Input Validation

    A critical flaw in UniFi Protect lets a low-privileged, network-adjacent attacker inject OS commands on the host device. Patch to 7.2.105+.

  • SecurityAug 6, 2026

    CVE-2026-66747: Zbtlink Routers Ship ENDLESSDOORS Firmware Backdoor (CVSS 9.8)

    Every published Zbtlink router firmware build contains ENDLESSDOORS — an embedded root-level remote control implant disguised as a Linux kernel worker thread, giving attackers persistent backdoor access to the device.

  • SecurityAug 5, 2026

    CVE-2026-61514: Puwell IP Camera Authentication Bypass

    A critical authentication bypass in Puwell IP Camera firmware 2.x through 4.x allows unauthenticated attackers to access live video streams, control pan/tilt/audio functions, and restart devices over the network with no credentials required.

  • SecurityAug 5, 2026

    CVE-2026-61515: Puwell IP Camera Unauthenticated Command Injection

    A critical unauthenticated command injection vulnerability in Puwell IP Camera firmware 2.x through 4.x allows remote attackers to execute arbitrary OS commands as root via the device's exposed DebugShell interface on TCP port 34567. No patch is available.

  • NewsJul 26, 2026

    LG to Ban Residential Proxies from Smart TV Apps

    LG Electronics USA announced it will suspend Smart TV apps that enroll viewers' televisions into residential proxy networks — a move triggered by research revealing that more than 42% of webOS games and apps were silently turning LG TVs into always-on proxy nodes without user knowledge or consent.

  • SecurityJul 7, 2026

    CVE-2026-24013: Apache IoTDB Authentication Bypass via Forged Session ID

    A critical authentication bypass in Apache IoTDB allows unauthenticated attackers to forge Thrift RPC session IDs and receive valid time-series query...

  • SecurityJul 7, 2026

    CVE-2026-24014: Apache IoTDB DataNode Path Traversal via Trigger JAR Upload

    A critical path traversal vulnerability in Apache IoTDB's DataNode RPC interface allows unauthenticated attackers to write arbitrary files outside the...

  • SecurityJun 26, 2026

    GeoVision LPC Camera Critical RCE via thttpd Buffer Overflow (CVE-2026-57878)

    A critical unauthenticated stack-based buffer overflow in thttpd on GeoVision GV-LPC2011 and GV-LPC2211 cameras allows remote attackers to execute...

  • SecurityJun 26, 2026

    GeoVision LPC Camera Critical RCE via ssvr RTSP Auth Buffer Overflow (CVE-2026-57879)

    A critical unauthenticated stack-based buffer overflow in the ssvr RTSP service of GeoVision GV-LPC2011 and GV-LPC2211 cameras allows remote attackers to...

  • SecurityJun 26, 2026

    GeoVision LPC Camera Critical RCE via ssvr RTSP Digest Auth Buffer Overflow (CVE-2026-57880)

    A critical unauthenticated stack-based buffer overflow in GeoVision GV-LPC2011 and GV-LPC2211 cameras allows remote code execution by exploiting...

  • SecurityJun 26, 2026

    GeoVision LPC Camera Critical RCE via vlsvr Remote Login Buffer Overflow (CVE-2026-57881)

    A critical unauthenticated stack-based buffer overflow in the vlsvr daemon of GeoVision GV-LPC2011 and GV-LPC2211 cameras allows remote code execution...

  • NewsMay 22, 2026

    Alleged Kimwolf Botmaster ''Dort'' Arrested, Charged in U.S. and Canada

    Canadian authorities arrested a 23-year-old Ottawa man suspected of building and operating Kimwolf, an IoT botnet that enslaved millions of devices for...

  • NewsMay 22, 2026

    US and Canada Arrest and Charge Suspected Kimwolf Botnet

    U.S. and Canadian authorities arrested and charged a Canadian man with operating the Kimwolf DDoS botnet, which infected nearly two million devices...

  • NewsMay 1, 2026

    EnOcean SmartServer Flaws Expose Buildings to Remote Hacking

    Claroty researchers have disclosed two vulnerabilities in the EnOcean SmartServer IQ building management controller that can be chained for security...

  • SecurityApr 28, 2026

    CVE-2026-7136: Totolink A8000RU OS Command Injection via setDmzCfg

    A critical OS command injection vulnerability in the Totolink A8000RU router allows remote attackers to execute arbitrary commands by manipulating the...

  • NewsApr 18, 2026

    Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack

    Threat actors are deploying the Nexcorium Mirai botnet variant by exploiting CVE-2024-3721 in TBK DVR devices and targeting end-of-life TP-Link Wi-Fi...

  • NewsApr 9, 2026

    ThreatsDay Bulletin: Hybrid P2P Botnet, 13-Year-Old Apache

    This week's ThreatsDay Bulletin from The Hacker News covers 20 active threats including a hybrid P2P DDoS botnet, a 13-year-old Apache ActiveMQ RCE flaw...

  • SecurityApr 4, 2026

    CVE-2026-28766: Gardyn Smart Garden API Exposes All User

    A critical unauthenticated information disclosure vulnerability in the Gardyn smart garden platform exposes all registered user account information via a...

  • SecurityFeb 18, 2026

    Critical Grandstream VoIP Vulnerability Allows

    A critical CVSS 9.3 stack-based buffer overflow in Grandstream GXP1600 series VoIP phones allows unauthenticated remote code execution, enabling attackers...