Overview
Description
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanMTU2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Statistics
- 1 Post
- 3 Interactions
Last activity: 8 hours ago
Overview
Description
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the cloneType2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Statistics
- 1 Post
- 3 Interactions
Last activity: 8 hours ago
Overview
Description
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the serviceName2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Statistics
- 1 Post
- 3 Interactions
Last activity: 8 hours ago
Overview
Description
Tenda AX-3 v16.03.12.10_CN was discovered to contain a stack overflow in the wanSpeed2 parameter of the fromAdvSetMacMtuWan function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
Statistics
- 1 Post
- 3 Interactions
Last activity: 8 hours ago
Overview
- NETGEAR
- XR1000v2
13 Jan 2026
Published
13 Jan 2026
Updated
CVSS v4.0
MEDIUM (6.1)
EPSS
Pending
KEV
Description
An insufficient input validation vulnerability in the NETGEAR XR1000v2
allows attackers connected to the router's LAN to execute OS command
injections.
Statistics
- 1 Post
- 2 Interactions
Last activity: 7 hours ago
Overview
Description
An insufficient input validation vulnerability in NETGEAR Orbi routers
allows attackers connected to the router's LAN to execute OS command
injections.
Statistics
- 1 Post
- 2 Interactions
Last activity: 7 hours ago
Overview
- NETGEAR
- RBRE960
13 Jan 2026
Published
13 Jan 2026
Updated
CVSS v4.0
MEDIUM (4.8)
EPSS
Pending
KEV
Description
An insufficient input validation vulnerability in NETGEAR Orbi devices'
DHCPv6 functionality allows network adjacent attackers authenticated
over WiFi or on LAN to execute OS command injections on the router.
DHCPv6 is not enabled by default.
Statistics
- 1 Post
- 2 Interactions
Last activity: 7 hours ago
Overview
- NETGEAR
- RBE970
13 Jan 2026
Published
13 Jan 2026
Updated
CVSS v4.0
MEDIUM (6.1)
EPSS
Pending
KEV
Description
An authentication bypass vulnerability in NETGEAR Orbi devices allows
users connected to the local network to access the router web interface
as an admin.
Statistics
- 1 Post
- 2 Interactions
Last activity: 7 hours ago
Overview
- NETGEAR
- EX5000
13 Jan 2026
Published
13 Jan 2026
Updated
CVSS v4.0
MEDIUM (6.1)
EPSS
Pending
KEV
Description
An insufficient authentication vulnerability in NETGEAR WiFi range
extenders allows a network adjacent attacker with WiFi authentication or
a physical Ethernet port connection to bypass the authentication
process and access the admin panel.
Statistics
- 1 Post
- 2 Interactions
Last activity: 7 hours ago
Overview
- NETGEAR
- EX5000
13 Jan 2026
Published
13 Jan 2026
Updated
CVSS v4.0
MEDIUM (6.1)
EPSS
Pending
KEV
Description
A path traversal vulnerability in NETGEAR WiFi range extenders allows
an attacker with LAN authentication to access the router's IP and
review the contents of the dynamically generated webproc file, which
records the username and password submitted to the router GUI.
Statistics
- 1 Post
- 2 Interactions
Last activity: 7 hours ago