Overview
Description
Statistics
- 1 Post
Overview
- D-Link
- DIR-823X
Description
Statistics
- 1 Post
Fediverse
π¨ HIGH severity: CVE-2026-2129 in D-Link DIR-823X (v250416) enables unauthenticated remote OS command injection via /goform/set_ac_status. Exploit code is public β patch or restrict access now! https://radar.offseq.com/threat/cve-2026-2129-os-command-injection-in-d-link-dir-8-54513fc4 #OffSeq #DLink #RouterSecurity
Overview
- Shenzhen Tenda Technology
- Tenda G300-F
Description
Statistics
- 1 Post
Fediverse
β οΈ CVE-2026-25857: HIGH-severity OS command injection in Tenda G300-F routers (β€16.01.14.2). No patch yet β exposure of management interface risks full device compromise. Restrict access, monitor WAN diagnostics. Details: https://radar.offseq.com/threat/cve-2026-25857-cwe-78-improper-neutralization-of-s-97d5f696 #OffSeq #Infosec #Vuln
Overview
- quickjs-ng
- quickjs
Description
Statistics
- 1 Post
Overview
- quickjs-ng
- quickjs
Description
Statistics
- 1 Post
Overview
Description
Statistics
- 1 Post
Fediverse
Apache Tomcat is far and away the most likely intended target given port 8080 and the Java exception body content. The DefaultServlet with readonly=false in web.xml is the textbook case (CVE-2017-12615, CVE-2017-12617). Eclipse Jetty can also expose similar behavior if its DefaultServlet or WebDAV module is configured to allow PUT writes. Apache TomEE, being Tomcat-based with Jakarta EE extensions, inherits all of the same misconfigurations. (5/15)
Overview
Description
Statistics
- 1 Post
Fediverse
Apache Tomcat is far and away the most likely intended target given port 8080 and the Java exception body content. The DefaultServlet with readonly=false in web.xml is the textbook case (CVE-2017-12615, CVE-2017-12617). Eclipse Jetty can also expose similar behavior if its DefaultServlet or WebDAV module is configured to allow PUT writes. Apache TomEE, being Tomcat-based with Jakarta EE extensions, inherits all of the same misconfigurations. (5/15)