Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2981+ Articles
168+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
25 articles

#Router Security

All CosmicBytez Labs articles tagged #Router Security, across news, security advisories, how-to guides, and projects.

  • SecuritySep 21, 2026

    CVE-2026-94003: Perfect-10 Stack Buffer Overflow in Comfast CF-N1-S Routers

    Comfast CF-N1-S 2.6.0.1's mbox-config CGI handler allows unauthenticated, network-based stack buffer overflow scoring a maximum CVSS 10.0.

  • SecuritySep 21, 2026

    CVE-2026-94089: Critical Unauthenticated Stack Overflow in D-Link DIR-868L Routers

    A CVSS 10 stack-based buffer overflow in D-Link DIR-868L's authentication CGI lets unauthenticated remote attackers achieve full router compromise.

  • SecuritySep 21, 2026

    CVE-2026-94095: Netcore NBR200V2 Traceroute Command Injection Enables Root RCE

    An unauthenticated command injection in Netcore NBR200V2's traceroute tool lets attackers run arbitrary commands as root via ubus JSON-RPC.

  • SecuritySep 21, 2026

    CVE-2026-94096: Command Injection in Netcore NBR200V2 LAN IP Configuration Handler

    Netcore NBR200V2 routers are vulnerable to unauthenticated command injection via the ipv4 argument in the LAN IP configuration handler.

  • SecuritySep 21, 2026

    CVE-2026-94097: Netcore NBR200V2 CGI Diagnostic Endpoint Command Injection

    A third command injection flaw in Netcore NBR200V2's network_tools CGI endpoint lets remote attackers run arbitrary shell commands unauthenticated.

  • SecuritySep 21, 2026

    CVE-2026-94098: Command Injection in Netcore NBR200V2 Firmware Upgrade Endpoint

    Netcore NBR200V2's firmware upgrade CGI endpoint injects the QUERY_STRING argument into a shell command, enabling unauthenticated remote injection.

  • SecuritySep 21, 2026

    CVE-2026-94099: Command Injection in Netcore NBR200V2 Backup Restore Endpoint

    The restore.cgi backup-restore endpoint on Netcore NBR200V2 routers is vulnerable to unauthenticated command injection via QUERY_STRING.

  • SecuritySep 21, 2026

    CVE-2026-94100: Buffer Overflow in Netcore NBR200V2 WAN VLAN Reconfiguration

    A buffer overflow in Netcore NBR200V2's routerd WAN VLAN handler can be triggered remotely via the vlan_wanX.ports argument.

  • SecuritySep 20, 2026

    CVE-2026-93958: D-Link R95 (BE9500) Command Injection to Root RCE

    A public PoC chains D-Link R95 BE9500 firmware 1.00.16's SetTimeSettings handler into authenticated command injection for root shell access.

  • SecuritySep 14, 2026

    Critical Stack Overflow in D-Link DIR-823G Routers (CVE-2026-90680)

    An unauthenticated stack-based buffer overflow (CVSS 9.9) in D-Link DIR-823G's HNAP1 interface allows remote attackers to corrupt memory...

  • SecuritySep 12, 2026

    CVE-2026-89009: WAVLINK Router Unauthenticated Arbitrary File Write

    WAVLINK WN535M1/WN535M3 routers let unauthenticated attackers overwrite any file on the device via the root sync_server daemon.

  • SecuritySep 12, 2026

    CVE-2026-89010: WAVLINK Router Unauthenticated Root Command Injection

    A critical OS command injection in WAVLINK WN535M1/WN535M3 routers lets unauthenticated attackers run root commands via sync_server.

  • NewsSep 6, 2026

    Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

    CERT Polska warns of active attacks gaining full admin control of internet-facing MikroTik RouterOS devices via SSH with no authentication needed.

  • SecurityAug 30, 2026

    TOTOLINK A720R Router: Unauthenticated Memory Corruption RCE (CVE-2026-82539)

    CVE-2026-82539 (CVSS 9.4) lets remote attackers corrupt memory in TOTOLINK A720R routers via the MAC filtering CGI handler. Public PoC exists.

  • SecurityAug 23, 2026

    CVE-2026-78050: Critical Stack Buffer Overflow in Comfast CF-N1-S Router

    CVSS 9.9 stack overflow in Comfast CF-N1-S 2.6.0.1 NTP timezone endpoint enables unauthenticated remote code execution.

  • SecurityAug 9, 2026

    CVE-2026-71948: D-Link DWR-M961 Command Injection via formDebugDiagnosticRun

    A critical unauthenticated command injection vulnerability in D-Link DWR-M961 routers allows remote attackers to execute arbitrary commands via the host field in the formDebugDiagnosticRun interface. CVSS 9.8.

  • SecurityAug 9, 2026

    CVE-2026-71949: D-Link DWR-M961 Command Injection via formUSSDSetup

    A critical unauthenticated command injection vulnerability in D-Link DWR-M961 routers enables remote code execution through the ussdValue and selectMenuValue fields in the formUSSDSetup interface. CVSS 9.8.

  • SecurityAug 9, 2026

    CVE-2026-71950: D-Link DWR-M961 Command Injection via formSmsManage

    A critical unauthenticated command injection in the D-Link DWR-M961 SMS management interface allows remote attackers to execute arbitrary OS commands via the action_value field. CVSS 9.8.

  • SecurityAug 9, 2026

    CVE-2026-71951: D-Link DWR-M961 Command Injection via formIMEISetup

    A critical unauthenticated command injection vulnerability in D-Link DWR-M961 routers allows remote code execution by injecting OS commands into the IMEI_value field of the formIMEISetup interface. CVSS 9.8.

  • SecurityJul 2, 2026

    CVE-2026-52186: Critical SQL Injection RCE in UTT nv518G Router

    A critical SQL injection vulnerability (CVSS 9.8) in the UTT nv518G router allows unauthenticated remote attackers to execute arbitrary code via the...

  • NewsJun 22, 2026

    AryStinger Malware Infects 4,300 Legacy Routers to Build Reconnaissance Proxy Network

    Researchers at QiAnXin's XLab have identified AryStinger, a novel malware targeting end-of-life D-Link routers and QNAP NAS devices to build a distributed...

  • NewsJun 3, 2026

    Acer Working to Patch Max Severity Zero-Days in Wave 7 Routers

    Acer is scrambling to address two maximum-severity zero-day vulnerabilities discovered in its Wave 7 mesh router lineup. Both flaws carry a CVSS score of 10.0…

  • NewsMay 22, 2026

    ThreatsDay Bulletin: Linux Rootkits, Router 0-Day, AI

    This week's threat intelligence bulletin covers Linux rootkit campaigns, an actively exploited router zero-day, AI-assisted intrusions, new scam kit...

  • NewsApr 7, 2026

    Authorities Disrupt APT28 Router DNS Hijacks Targeting

    An international law enforcement operation has dismantled FrostArmada, an APT28 campaign that hijacked DNS on compromised MikroTik and TP-Link routers to...

  • NewsletterApr 7, 2026

    Apr 7 Digest: Medusa Ransomware Surge, FBI $21B Record

    Storm-1175 runs sub-24-hour Medusa ransomware campaigns using zero-days; the FBI IC3 reports a record $21 billion in US cybercrime losses for 2025; North...