Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2614+ Articles
162+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
40 articles

#Router

All CosmicBytez Labs articles tagged #Router, across news, security advisories, how-to guides, and projects.

  • SecurityAug 31, 2026

    Critical Unauthenticated Buffer Overflow in Tenda HG10 Routers

    CVE-2026-82542 (CVSS 10) lets remote attackers trigger a buffer overflow in Tenda HG10 routers via the formIPv6Routing handler. Public exploit exists.

  • SecurityAug 31, 2026

    D-Link DIR-825M Disk-Format Stack Overflow (CVE-2026-82592)

    CVE-2026-82592 is a critical, unauthenticated stack overflow in D-Link DIR-825M's disk-formatting endpoint, with a public exploit available.

  • SecurityAug 31, 2026

    D-Link DIR-825M LTE Upgrade Stack Overflow (CVE-2026-82593)

    CVE-2026-82593 is a critical, unauthenticated stack overflow in D-Link DIR-825M's LTE firmware-upgrade handler, with a public exploit available.

  • SecurityAug 17, 2026

    CVE-2026-19961: Critical Buffer Overflow in Edimax EW-7478APC Wireless Router

    A CVSS 9.9 buffer overflow in the Edimax EW-7478APC 1.04 allows unauthenticated remote code execution via the formWlSiteSurvey endpoint.

  • SecurityAug 17, 2026

    CVE-2026-19977: EFM ipTIME A3004T Authentication Bypass — CVSS 10.0

    Critical auth bypass (CVSS 10.0) in EFM ipTIME A3004T routers lets unauthenticated attackers gain full admin access via session URL manipulation.

  • NewsAug 15, 2026

    New Evooo1Bot Linux Botnet Turns Routers Into Traffic Relay Nodes

    FortiGuard Labs uncovers Evooo1Bot, a Mirai-derived Linux botnet exploiting 8 CVEs to compromise routers and convert them into persistent SOCKS5 relay proxies.

  • NewsAug 10, 2026

    Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

    This week's security roundup covers agentic AI containment failures, a critical Metabase zero-day, malicious MCP plugins targeting AI assistants, and persistent router firmware backdoors.

  • SecurityAug 9, 2026

    D-Link DWR-M961 Command Injection via FOTA Upgrade Interface (Quectel)

    A command injection vulnerability in D-Link DWR-M961 routers (hardware C1) allows remote attackers to execute arbitrary OS commands via the fota_url parameter in the Quectel FOTA upgrade interface.

  • SecurityAug 9, 2026

    D-Link DWR-M961 Command Injection via FOTA Upgrade Interface (Fibocom)

    A command injection vulnerability in D-Link DWR-M961 routers (hardware C1) allows remote attackers to execute arbitrary OS commands via the fota_url parameter in the Fibocom FOTA upgrade interface.

  • SecurityAug 9, 2026

    D-Link DWR-M961 Command Injection via Ping Diagnostic Interface

    A command injection vulnerability in D-Link DWR-M961 routers (hardware C1) allows remote attackers to execute arbitrary OS commands via the host parameter in the ping diagnostic interface.

  • SecurityAug 9, 2026

    D-Link DWR-M961 Command Injection via Traceroute Diagnostic Interface

    A command injection vulnerability in D-Link DWR-M961 routers (hardware C1) allows remote attackers to execute arbitrary OS commands via the host and ipVer parameters in the traceroute diagnostic interface.

  • SecurityAug 9, 2026

    MSI Radix AXE6600 Critical Command Injection in WPS Interface (CVE-2026-71983)

    A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's wps.cgi interface allows remote attackers to execute arbitrary commands as root by injecting malicious input through unsanitized WPS PIN parameters.

  • SecurityAug 9, 2026

    MSI Radix AXE6600 Critical Command Injection in URL Filter Function (CVE-2026-71984)

    A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's urlfilter function allows remote attackers to execute arbitrary commands as root, enabling full device takeover via the URL filtering management interface.

  • SecurityAug 9, 2026

    MSI Radix AXE6600 Critical Command Injection in Access Control Function (CVE-2026-71985)

    A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's accesscontrol function enables remote attackers to execute arbitrary commands as root, bypassing network access restrictions and achieving full device compromise.

  • SecurityAug 9, 2026

    MSI Radix AXE6600 Critical Command Injection in DMZ Function (CVE-2026-71986)

    A critical CVSS 9.8 command injection vulnerability in the MSI Radix AXE6600 router's DMZ function allows remote attackers to execute arbitrary commands as root, completing a cluster of four critical command injection flaws in firmware v781521.

  • SecurityAug 6, 2026

    CVE-2026-66747: Zbtlink Routers Ship ENDLESSDOORS Firmware Backdoor (CVSS 9.8)

    Every published Zbtlink router firmware build contains ENDLESSDOORS — an embedded root-level remote control implant disguised as a Linux kernel worker thread, giving attackers persistent backdoor access to the device.

  • SecurityAug 4, 2026

    CVE-2026-18602: GL.iNet GL-MT3000 Remote Command Injection via VPN Hostname

    A critical command injection vulnerability in GL.iNet GL-MT3000 routers (firmware up to 4.4.5) allows remote attackers to execute arbitrary OS commands by manipulating the Hostname argument in the OpenVPN client configuration endpoint.

  • SecurityJul 21, 2026

    CVE-2024-51311: Critical Stack Overflow in Tenda TX9 Router Firmware

    A critical stack overflow vulnerability (CVSS 9.8) in Tenda TX9 firmware V22.03.02.05 allows remote attackers to execute arbitrary code via a crafted...

  • SecurityJul 16, 2026

    CVE-2026-51380: Tenda AC10 v3 Buffer Overflow Enables DoS and Remote Code Execution

    A critical CVSS 9.8 buffer overflow vulnerability in Tenda AC10 v3 firmware V03.03.16.09 allows remote attackers to cause permanent denial of service or...

  • SecurityJul 13, 2026

    CVE-2026-15511: Critical OS Command Injection in Comfast CF-WR631AX Router

    A CVSS 9.8 critical OS command injection vulnerability in the Comfast CF-WR631AX V3 router allows unauthenticated network-adjacent attackers to execute...

  • SecurityJun 5, 2026

    CVE-2026-35906: T3 Technology CPE Unauthenticated Root RCE via Debug CGI

    An undocumented debug CGI endpoint in T3 Technology CPE devices (T625Pro v1.0.07, T6825G v1.0.03) allows unauthenticated remote attackers to execute arbitrary…

  • SecurityJun 5, 2026

    CVE-2026-6274: Critical Authentication Bypass in DTS Redline WR3200 Router

    A critical authentication bypass vulnerability in the DTS Electronics Redline WR3200 router allows unauthenticated attackers to access functionality protected…

  • SecurityJun 1, 2026

    CVE-2026-10187: Totolink N300RH Stack Buffer Overflow in WiFi Config

    A critical-severity stack buffer overflow in the Totolink N300RH wireless router allows remote attackers to execute arbitrary code via a crafted KeyStr…

  • SecurityMay 1, 2026

    Critical Stack-Based Buffer Overflow in Totolink NR1800X

    A critical CVSS 9.8 stack-based buffer overflow in the Totolink NR1800X router's lighttpd component allows unauthenticated remote code execution via a...

  • SecurityApr 30, 2026

    CVE-2026-36841: TOTOLINK N200RE V5 Command Injection

    A critical CVSS 9.8 command injection vulnerability in TOTOLINK N200RE V5 allows unauthenticated remote code execution via the macstr and bandstr...

  • SecurityApr 28, 2026

    CVE-2026-7136: Totolink A8000RU OS Command Injection via setDmzCfg

    A critical OS command injection vulnerability in the Totolink A8000RU router allows remote attackers to execute arbitrary commands by manipulating the...

  • SecurityApr 28, 2026

    CVE-2026-7154: Totolink A8000RU OS Command Injection via CGI Handler

    A critical unauthenticated OS command injection vulnerability in the Totolink A8000RU router firmware 7.1cu.643_b20200521 allows remote attackers to...

  • SecurityApr 27, 2026

    CVE-2026-7037: Unauthenticated OS Command Injection in Totolink A8000RU

    A critical CVSS 9.8 OS command injection vulnerability in the Totolink A8000RU router allows unauthenticated remote attackers to execute arbitrary...

  • SecurityApr 25, 2026

    CVE-2025-29635: D-Link DIR-823X Command Injection

    A command injection flaw in end-of-life D-Link DIR-823X routers allows authenticated remote attackers to execute arbitrary OS commands. CISA has added...

  • SecurityApr 12, 2026

    CVE-2026-6112: Totolink A7100RU OS Command Injection via setRadvdCfg

    A critical OS command injection vulnerability (CVSS 9.8) in Totolink A7100RU firmware allows unauthenticated remote attackers to execute arbitrary...

  • SecurityApr 12, 2026

    CVE-2026-6113: Totolink A7100RU OS Command Injection via setTtyServiceCfg

    A critical OS command injection flaw (CVSS 9.8) in Totolink A7100RU enables remote unauthenticated attackers to execute arbitrary commands by manipulating...

  • SecurityApr 12, 2026

    CVE-2026-6114: Totolink A7100RU OS Command Injection via setNetworkCfg

    CVE-2026-6114 is a critical OS command injection vulnerability (CVSS 9.8) in the Totolink A7100RU router's setNetworkCfg function, exploitable remotely...

  • SecurityApr 12, 2026

    CVE-2026-6115: Totolink A7100RU OS Command Injection via setAppCfg

    CVE-2026-6115 describes a critical OS command injection vulnerability (CVSS 9.8) in the Totolink A7100RU router, exploitable remotely and without...

  • SecurityApr 10, 2026

    CVE-2026-5977: TOTOLINK A7100RU Critical OS Command

    A critical OS command injection vulnerability (CVSS 9.8) in TOTOLINK A7100RU routers allows unauthenticated remote attackers to execute arbitrary system...

  • SecurityApr 10, 2026

    CVE-2026-5978: TOTOLINK A7100RU Critical OS Command

    A second critical OS command injection vulnerability (CVSS 9.8) in TOTOLINK A7100RU routers allows unauthenticated remote attackers to execute arbitrary...

  • SecurityApr 2, 2026

    CVE-2026-31027: TOTOlink A3600R Buffer Overflow in setAppEasyWizardConfig

    A critical CVSS 9.8 buffer overflow in TOTOlink A3600R v5.9c.4959 allows remote attackers to exploit the rootSsid parameter in the setAppEasyWizardConfig...

  • SecurityMar 23, 2026

    Tenda A15 UploadCfg Stack Buffer Overflow (CVE-2026-4567)

    A CVSS 9.8 Critical stack-based buffer overflow in Tenda A15 firmware 15.13.07.13 allows unauthenticated remote attackers to execute arbitrary code by...

  • SecurityMar 22, 2026

    D-Link DHP-1320 SOAP Handler Stack Buffer Overflow

    A CVSS 8.8 stack-based buffer overflow in D-Link DHP-1320 firmware 1.00WWB04 allows unauthenticated remote attackers to execute arbitrary code via a...

  • SecurityFeb 8, 2026

    Cisco IOS XE Web UI Privilege Escalation Actively Exploited

    Cisco discloses a high-severity privilege escalation vulnerability in IOS XE Web UI that allows authenticated users to gain root access. Active...

  • SecurityJan 18, 2026

    Critical D-Link Router RCE Under Active Exploitation - No

    CVE-2026-0625 allows unauthenticated remote code execution on legacy D-Link DSL routers. Devices are end-of-life with no patches forthcoming. Immediate...