All CosmicBytez Labs articles tagged #Router Security, across news, security advisories, how-to guides, and projects.
Comfast CF-N1-S 2.6.0.1's mbox-config CGI handler allows unauthenticated, network-based stack buffer overflow scoring a maximum CVSS 10.0.
A CVSS 10 stack-based buffer overflow in D-Link DIR-868L's authentication CGI lets unauthenticated remote attackers achieve full router compromise.
An unauthenticated command injection in Netcore NBR200V2's traceroute tool lets attackers run arbitrary commands as root via ubus JSON-RPC.
Netcore NBR200V2 routers are vulnerable to unauthenticated command injection via the ipv4 argument in the LAN IP configuration handler.
A third command injection flaw in Netcore NBR200V2's network_tools CGI endpoint lets remote attackers run arbitrary shell commands unauthenticated.
Netcore NBR200V2's firmware upgrade CGI endpoint injects the QUERY_STRING argument into a shell command, enabling unauthenticated remote injection.
The restore.cgi backup-restore endpoint on Netcore NBR200V2 routers is vulnerable to unauthenticated command injection via QUERY_STRING.
A buffer overflow in Netcore NBR200V2's routerd WAN VLAN handler can be triggered remotely via the vlan_wanX.ports argument.
A public PoC chains D-Link R95 BE9500 firmware 1.00.16's SetTimeSettings handler into authenticated command injection for root shell access.
An unauthenticated stack-based buffer overflow (CVSS 9.9) in D-Link DIR-823G's HNAP1 interface allows remote attackers to corrupt memory...
WAVLINK WN535M1/WN535M3 routers let unauthenticated attackers overwrite any file on the device via the root sync_server daemon.
A critical OS command injection in WAVLINK WN535M1/WN535M3 routers lets unauthenticated attackers run root commands via sync_server.
CERT Polska warns of active attacks gaining full admin control of internet-facing MikroTik RouterOS devices via SSH with no authentication needed.
CVE-2026-82539 (CVSS 9.4) lets remote attackers corrupt memory in TOTOLINK A720R routers via the MAC filtering CGI handler. Public PoC exists.
CVSS 9.9 stack overflow in Comfast CF-N1-S 2.6.0.1 NTP timezone endpoint enables unauthenticated remote code execution.
A critical unauthenticated command injection vulnerability in D-Link DWR-M961 routers allows remote attackers to execute arbitrary commands via the host field in the formDebugDiagnosticRun interface. CVSS 9.8.
A critical unauthenticated command injection vulnerability in D-Link DWR-M961 routers enables remote code execution through the ussdValue and selectMenuValue fields in the formUSSDSetup interface. CVSS 9.8.
A critical unauthenticated command injection in the D-Link DWR-M961 SMS management interface allows remote attackers to execute arbitrary OS commands via the action_value field. CVSS 9.8.
A critical unauthenticated command injection vulnerability in D-Link DWR-M961 routers allows remote code execution by injecting OS commands into the IMEI_value field of the formIMEISetup interface. CVSS 9.8.
A critical SQL injection vulnerability (CVSS 9.8) in the UTT nv518G router allows unauthenticated remote attackers to execute arbitrary code via the...
Researchers at QiAnXin's XLab have identified AryStinger, a novel malware targeting end-of-life D-Link routers and QNAP NAS devices to build a distributed...
Acer is scrambling to address two maximum-severity zero-day vulnerabilities discovered in its Wave 7 mesh router lineup. Both flaws carry a CVSS score of 10.0…
This week's threat intelligence bulletin covers Linux rootkit campaigns, an actively exploited router zero-day, AI-assisted intrusions, new scam kit...
An international law enforcement operation has dismantled FrostArmada, an APT28 campaign that hijacked DNS on compromised MikroTik and TP-Link routers to...
Storm-1175 runs sub-24-hour Medusa ransomware campaigns using zero-days; the FBI IC3 reports a record $21 billion in US cybercrime losses for 2025; North...