All CosmicBytez Labs articles tagged #Router Vulnerability, across news, security advisories, how-to guides, and projects.
D-Link DWR-M920 1.1.7 lets remote attackers inject OS commands through the formPinManageSetup handler; a public exploit is already available.
D-Link DWR-M921 1.1.52 lets remote attackers inject OS commands through the formDiskFormat handler; a public exploit is already available.
D-Link DWR-M921 1.1.52 lets remote attackers inject OS commands through the formDiskCreateShare handler; a public exploit is already available.
CVSS 10.0 flaw in Tenda CP3's Kylin AutoAddWifi thread lets remote attackers inject and execute arbitrary OS commands.
Tenda CP3 firmware 27.5.57.101 lets remote attackers inject OS commands through its network configuration handler, no authentication noted.
Tenda CP3's SetRedirectEnable function lacks authorization checks, letting remote attackers alter port-forwarding without admin access.