Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 10 TALOSBLOG:ACBB9...

Russian state-sponsored espionage group Static Tundra compromises unpatched end-of-life network devices_TALOSBLOG:ACBB9485DF45A4C6226DBC1BA95C3A94

* **Static Tundra is a Russian state-sponsored cyber espionage group** linked to the FSB's Center 16 unit that has been operating for over a decade...

N/A N/A TALOSBLOG
HIGH 8.8 CVE-2025-50503

CVE-2025-50503_CVE-2025-50503

A vulnerability in the password reset workflow of the Touch Lebanon Mobile App 2.20.2 allows an attacker to bypass the OTP reset password mechanism...

n/a n/a n/a CVE
HIGH 7.3 CVE-2025-55503

CVE-2025-55503_CVE-2025-55503

Tenda AC6 V15.03.06.23_multi has a stack overflow vulnerability via the deviceName parameter in the saveParentControlInfo function.

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-54924

CVE-2025-54924_CVE-2025-54924

CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker sends a sp...

Schneider Electric EcoStruxure™ Power Monitoring Expert (PME) Version 2022 CVE
HIGH 8.7 CVE-2025-54923

CVE-2025-54923_CVE-2025-54923

CWE-502: Deserialization of Untrusted Data vulnerability exists that could cause remote code execution and compromise of system integrity when auth...

Schneider Electric EcoStruxure™ Power Monitoring Expert (PME) Version 2022 CVE
HIGH 7.2 CVE-2025-54926

CVE-2025-54926_CVE-2025-54926

CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause remote code execution ...

Schneider Electric EcoStruxure™ Power Monitoring Expert (PME) Version 2022 CVE
HIGH 7.5 CVE-2025-54925

CVE-2025-54925_CVE-2025-54925

CWE-918: Server-Side Request Forgery (SSRF) vulnerability exists that could cause unauthorized access to sensitive data when an attacker configures...

Schneider Electric EcoStruxure™ Power Monitoring Expert (PME) Version 2022 CVE
HIGH 8.1 CVE-2025-32010

CVE-2025-32010_CVE-2025-32010

A stack-based buffer overflow vulnerability exists in the Cloud API functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted HTTP respons...

Tenda AC6 V5.0 V02.03.01.110 CVE
HIGH 8.6 CVE-2025-30256

CVE-2025-30256_CVE-2025-30256

A denial of service vulnerability exists in the HTTP Header Parsing functionality of Tenda AC6 V5.0 V02.03.01.110. A specially crafted series of HT...

Tenda AC6 V5.0 V02.03.01.110 CVE
HIGH 7.5 CVE-2025-24496

CVE-2025-24496_CVE-2025-24496

An information disclosure vulnerability exists in the /goform/getproductInfo functionality of Tenda AC6 V5.0 V02.03.01.110. Specially crafted netwo...

Tenda AC6 V5.0 V02.03.01.110 CVE