2026-08-09
2026-08-09 00:16Z
CRIT

CVE-2026-71991 — MSI: Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71991

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the Telnet configuration interface to inject malicious commands and obtain root privileges on the underlying system. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDMsiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-09
2026-08-09 00:16Z
CRIT

CVE-2026-71990 — MSI: Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71990

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the SSH configuration interface to inject malicious commands and obtain root privileges on the underlying system. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDMsiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-09
2026-08-09 00:16Z
CRIT

CVE-2026-71989 — MSI: Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71989

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDMsiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-09
2026-08-09 00:16Z
CRIT

CVE-2026-71988 — MSI: Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71988

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDMsiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-09
2026-08-09 00:16Z
CRIT

CVE-2026-71987 — MSI: Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71987

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the alg function to execute malicious commands and obtain root privileges on the underlying system. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDMsiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-09
2026-08-09 00:16Z
CRIT

CVE-2026-71986 — MSI: Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71986

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the dmz function to execute malicious commands and obtain root privileges on the underlying system. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDMsiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-09
2026-08-09 00:16Z
CRIT

CVE-2026-71985 — MSI: Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71985

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit this vulnerability through the accesscontrol function to execute malicious commands and obtain root privileges on the underlying system. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDMsiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-08-09
2026-08-09 00:16Z
CRIT

CVE-2026-71984 — MSI: Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71984

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit the urlfilter function to inject malicious commands and obtain root privileges on the underlying system. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDMsiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-08
2026-08-08 23:16Z
CRIT

CVE-2026-71983 — MSI: Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71983

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to execute arbitrary commands by injecting malicious input through the pin2g, pin5g, or pin6g parameters. Attackers can exploit these unsanitized parameters to execute arbitrary commands on the affected device and obtain root privileges. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDMsiTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-08
2026-08-08 18:16Z
CRIT

CVE-2026-71958 — Link: D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71958

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup.cgi interface. A remote attacker can write overly long strings to the test4, ssid2, and username fields and execute arbitrary commands by crafting a specific payload, or cause the device to crash. CVSSv3.1 9.8 (CRITICAL)

CWECWE 120VNDLinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-08
2026-08-08 18:16Z
CRIT

CVE-2026-71957 — Link: D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71957

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAcc.addlist[].name field and execute arbitrary commands by crafting a specific payload, or cause the device to crash. CVSSv3.1 9.8 (CRITICAL)

CWECWE 120VNDLinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-08
2026-08-08 18:16Z
CRIT

CVE-2026-71956 — Link: D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71956

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi interface. A remote attacker can inject arbitrary malicious commands into the netDig.ping.dst field, resulting in command execution with root privileges. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDLinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-08
2026-08-08 17:16Z
CRIT

CVE-2026-71955 — Link: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71955

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formWsc interface. A remote attacker can inject arbitrary malicious commands into the localPin field, resulting in command execution with root privileges. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDLinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-08
2026-08-08 17:16Z
CRIT

CVE-2026-71954 — Link: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71954

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formL2tpv3ConfigSetup interface. A remote attacker can inject arbitrary malicious commands into the tunnelid and sessionid fields, resulting in command execution with root privileges. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDLinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-08
2026-08-08 17:16Z
CRIT

CVE-2026-71953 — Link: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71953

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formNtp interface. A remote attacker can inject arbitrary malicious commands into the ntpServerIp1 field, resulting in command execution with root privileges. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDLinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-08
2026-08-08 17:16Z
CRIT

CVE-2026-71952 — Link: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71952

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPinManageSetup interface. A remote attacker can inject arbitrary malicious commands into the oldPIn field, resulting in command execution with root privileges. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDLinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-08
2026-08-08 17:16Z
CRIT

CVE-2026-71951 — Link: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71951

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formIMEISetup interface. A remote attacker can inject arbitrary malicious commands into the IMEI_value field, resulting in command execution with root privileges. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDLinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-08
2026-08-08 17:16Z
CRIT

CVE-2026-71950 — Link: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71950

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formSmsManage interface. A remote attacker can inject arbitrary malicious commands into the action_value field, resulting in command execution with root privileges. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDLinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-08
2026-08-08 17:16Z
CRIT

CVE-2026-71949 — Link: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71949

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formUSSDSetup interface. A remote attacker can inject arbitrary malicious commands into the ussdValue and selectMenuValue fields, resulting in command execution with root privileges. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDLinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-08
2026-08-08 17:16Z
CRIT

CVE-2026-71948 — Link: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71948

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formDebugDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDLinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-08
2026-08-08 17:16Z
CRIT

CVE-2026-71947 — Link: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71947

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formTracerouteDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host and ipVer fields, resulting in command execution with root privileges. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDLinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-08
2026-08-08 17:16Z
CRIT

CVE-2026-71946 — Link: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71946

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formPingDiagnosticRun interface. A remote attacker can inject arbitrary malicious commands into the host field, resulting in command execution with root privileges. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDLinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-08
2026-08-08 17:16Z
CRIT

CVE-2026-71945 — Link: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71945

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeFibocom interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDLinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-08
2026-08-08 17:16Z
CRIT

CVE-2026-71944 — Link: D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-71944

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /boafrm/formLtefotaUpgradeQuectel interface. A remote attacker can inject arbitrary malicious commands into the fota_url field, resulting in command execution with root privileges. CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDLinkTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-08-08
2026-08-08 12:51Z
INFO

v3.11.1

Nuclei releases·github.com

Nuclei v3.11.1 released with incremental improvements including Lua script enhancements, metadata cache reuse for thread-safe scans, and multiple bug fixes across HTTP parsing, regex extraction, and headless rendering. The release includes dependency updates and new JavaScript client libraries for SMB, MySQL, and MSSQL fingerprinting.

SWNucleiVNDProjectdiscoveryTYPTool
35
Edit Score