CVE-2026-94003: CRITICAL stack buffer overflow in Comfast CF-N1-S (2.6.0.1). Flaw in get_css_path_from_uri (/cgi-bin/mbox-config) is remotely exploitable; public exploit exists. Restrict access & monitor closely. https://radar.offseq.com/threat/cve-2026-94003-stack-based-buffer-overflow-in-comfast-cf-n1-s-1046130f838f5eec #OffSeq #Infosec #CVE #IoTSecurity
About This Hashtag
#iotsecurity
15 posts
Last used 2h
#iotsecurity
15 posts· Last used 2h
EFM ipTIME C200E v1.094 suffers CRITICAL OS command injection (CVE-2026-90847, CVSS 9.4) via iux_set.cgi. Remotely exploitable, public exploit available. Restrict device access and monitor. https://radar.offseq.com/threat/cve-2026-90847-os-command-injection-in-efm-iptime-c200e-1c30057b126bbbf4 #OffSeq #Vulnerability #IoTSecurity #CVE
CVE-2026-87931 | CRITICAL buffer overflow in Pavlok Behavioral Conditioning Wearable (Apple Notification Center Service Event Handler). Exploitable locally, no patch or vendor response. Limit device network access. Details: https://radar.offseq.com/threat/cve-2026-87931-buffer-overflow-in-behavioral-technology-group-pavlok-behavioral-conditioning-wearable-98a2d4c4edee7864 #OffSeq #CVE202687931 #IoTSecurity
CISA advisory ICSA-26-251-01 documents CVE-2026-85083 in CareCam Pro ANJIA AJL33PC0801: hard-coded bootloader credential allows privileged access with physical presence. It enables firmware modification and persistent compromise, undermining trust in affected deployments. #HardcodedCredentials #IotSecurity #FirmwareSecurity
https://cyberworldops.eu/en/hard-coded-bootloader-credential-exposes-carecam-pro-camera-to-full
An OpenRemote vulnerability, CVE-2026-66013 (CVSS 9.3), enables unauthenticated asset takeover. Full advisory details are now public. Patch to 1.26.2.
#OpenRemote #CVE202666013 #IoTSecurity #AssetTakeover
https://securityonline.info/openremote-cve-2026-66013/?utm_source=mastodon&utm_medium=jetpack_social
CVE-2026-8983: Autel Maxi Charger Single ≤1.03.51 is affected by a CRITICAL flaw — hard-coded token bypasses authentication, exposing management endpoints. Restrict access & monitor for abuse. Patch status unknown. https://radar.offseq.com/threat/autel-maxi-charger-single-firmware-through-v10351-contains-a-hard-coded-authentication-token-that-cb2fec544a5f031e #OffSeq #CVE20268983 #IoTSecurity
A Shark robot vacuum vulnerability lets attackers run code remotely, hijack movement, and access cameras. Over 673,000 devices confirmed exposed, unpatched.
#Shark #SharkNinja #RCE #IoTSecurity #RobotVacuum #Vulnerability
https://meterpreter.org/shark-vacuum-rce/?utm_source=mastodon&utm_medium=jetpack_social
A TP-Link Kasa vulnerability (CVE-2026-9770) lets local attackers steal admin credentials via a hardcoded key. Patch your EC70 and EC71 firmware now.
#TPLink #Kasa #CVE20269770 #IoTSecurity #Cameras #ManInTheMiddle
https://meterpreter.org/tp-link-kasa-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
CVE-2026-42566 (HIGH): Meshtastic firmware <2.7.23.b246bcd suffers from improper input validation. Malformed User.long_name can poison BLE node DBs, causing iOS sync loops and device loss. Upgrade now. Details: https://radar.offseq.com/threat/cve-2026-42566-cwe-20-improper-input-validation-in-meshtastic-firmware-f4cb4608f8fc25f1 #OffSeq #infosec #CVE #IoTSecurity
TP-Link Kasa vulnerability CVE-2026-9770 (CVSS 8.6) lets local attackers intercept admin credentials on EC70 and EC71 cameras. Update firmware now.
#TPLink #Kasa #IoTSecurity #CVE20269770 #InfoDisclosure
https://securityonline.info/tp-link-kasa-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
Binarly found 6 U-Boot flaws including BRLY-2026-038 (CVSS 6.8) that allow pre-OS code execution on routers, servers, and IoT devices.
#UBoot #Binarly #FirmwareSecurity #BootloaderVulnerability #IoTSecurity
https://meterpreter.org/u-boot-vulnerabilities-binarly/?utm_source=mastodon&utm_medium=jetpack_social
Three Apache IoTDB vulnerabilities include a critical path traversal (CVE-2026-24014) and an authentication bypass. Upgrade to 2.0.8 now.
#ApacheIoTDB #PathTraversal #AuthBypass #CVE #IoTSecurity #InfoSec
https://securityonline.info/apache-iotdb-vulnerabilities/?utm_source=mastodon&utm_medium=jetpack_social
🤖 Hidden authentication backdoor discovered in Tenda router firmware (multiple models). Unauthenticated attackers can obtain admin access to the web management panel.
🔗 https://www.bleepingcomputer.com/news/security/hidden-backdoor-in-tenda-router-firmware-grants-admin-access/
#Tenda #Backdoor #IoTSecurity #CyberSec
CVE-2026-13768: Gardyn Home Firmware (CRITICAL, CVSS 10) exposes a privileged iothubowner key, enabling attackers to control devices & move laterally on networks. No patch yet. Monitor and segment IoT devices. https://radar.offseq.com/threat/cve-2026-13768-cwe-798-in-gardyn-gardyn-home-firmw-08332214fc38f3ba #OffSeq #IoTSecurity #CVE202613768
H.VIEW HV-500S6 IP Camera has a HIGH severity bug (CVE-2026-55975, CVSS 7.2): Authenticated users may inject commands using unsanitized XML in cert generation. Restrict access, monitor activity, and check for patches. https://radar.offseq.com/threat/cve-2026-55975-cwe-78-in-hview-hv-500s6-ip-camera-32fd47fcf53b8f7c #OffSeq #Vulnerability #IoTSecurity 🔒
You've seen all posts