diff --git a/advisories/unreviewed/2022/12/GHSA-8wrq-79wc-jr56/GHSA-8wrq-79wc-jr56.json b/advisories/unreviewed/2022/12/GHSA-8wrq-79wc-jr56/GHSA-8wrq-79wc-jr56.json index d8559bb6244..3b67e5d0de9 100644 --- a/advisories/unreviewed/2022/12/GHSA-8wrq-79wc-jr56/GHSA-8wrq-79wc-jr56.json +++ b/advisories/unreviewed/2022/12/GHSA-8wrq-79wc-jr56/GHSA-8wrq-79wc-jr56.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2022/12/GHSA-xrxj-jg56-83p4/GHSA-xrxj-jg56-83p4.json b/advisories/unreviewed/2022/12/GHSA-xrxj-jg56-83p4/GHSA-xrxj-jg56-83p4.json index 9ca701659ba..cf28470fb19 100644 --- a/advisories/unreviewed/2022/12/GHSA-xrxj-jg56-83p4/GHSA-xrxj-jg56-83p4.json +++ b/advisories/unreviewed/2022/12/GHSA-xrxj-jg56-83p4/GHSA-xrxj-jg56-83p4.json @@ -26,7 +26,8 @@ ], "database_specific": { "cwe_ids": [ - "CWE-77" + "CWE-77", + "CWE-78" ], "severity": "HIGH", "github_reviewed": false, diff --git a/advisories/unreviewed/2024/06/GHSA-45xf-mpvq-5ggq/GHSA-45xf-mpvq-5ggq.json b/advisories/unreviewed/2024/06/GHSA-45xf-mpvq-5ggq/GHSA-45xf-mpvq-5ggq.json index 4e6023bdcb8..c116d0ad16e 100644 --- a/advisories/unreviewed/2024/06/GHSA-45xf-mpvq-5ggq/GHSA-45xf-mpvq-5ggq.json +++ b/advisories/unreviewed/2024/06/GHSA-45xf-mpvq-5ggq/GHSA-45xf-mpvq-5ggq.json @@ -26,6 +26,7 @@ ], "database_specific": { "cwe_ids": [ + "CWE-129", "CWE-400" ], "severity": "HIGH", diff --git a/advisories/unreviewed/2024/07/GHSA-g345-r3xq-7xxq/GHSA-g345-r3xq-7xxq.json b/advisories/unreviewed/2024/07/GHSA-g345-r3xq-7xxq/GHSA-g345-r3xq-7xxq.json index 1051be91806..b624aa9c6f6 100644 --- a/advisories/unreviewed/2024/07/GHSA-g345-r3xq-7xxq/GHSA-g345-r3xq-7xxq.json +++ b/advisories/unreviewed/2024/07/GHSA-g345-r3xq-7xxq/GHSA-g345-r3xq-7xxq.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-79" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-w4hr-5x27-752x/GHSA-w4hr-5x27-752x.json b/advisories/unreviewed/2024/07/GHSA-w4hr-5x27-752x/GHSA-w4hr-5x27-752x.json index 34a4ca702cc..0fd8b02b2d0 100644 --- a/advisories/unreviewed/2024/07/GHSA-w4hr-5x27-752x/GHSA-w4hr-5x27-752x.json +++ b/advisories/unreviewed/2024/07/GHSA-w4hr-5x27-752x/GHSA-w4hr-5x27-752x.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2024/07/GHSA-wh4c-fpvw-r5xc/GHSA-wh4c-fpvw-r5xc.json b/advisories/unreviewed/2024/07/GHSA-wh4c-fpvw-r5xc/GHSA-wh4c-fpvw-r5xc.json index ea57b04cc23..af48124c771 100644 --- a/advisories/unreviewed/2024/07/GHSA-wh4c-fpvw-r5xc/GHSA-wh4c-fpvw-r5xc.json +++ b/advisories/unreviewed/2024/07/GHSA-wh4c-fpvw-r5xc/GHSA-wh4c-fpvw-r5xc.json @@ -25,7 +25,9 @@ } ], "database_specific": { - "cwe_ids": [], + "cwe_ids": [ + "CWE-352" + ], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, diff --git a/advisories/unreviewed/2025/04/GHSA-7w9p-pr7x-mjw2/GHSA-7w9p-pr7x-mjw2.json b/advisories/unreviewed/2025/04/GHSA-7w9p-pr7x-mjw2/GHSA-7w9p-pr7x-mjw2.json index 43f6d64fb81..e075115201f 100644 --- a/advisories/unreviewed/2025/04/GHSA-7w9p-pr7x-mjw2/GHSA-7w9p-pr7x-mjw2.json +++ b/advisories/unreviewed/2025/04/GHSA-7w9p-pr7x-mjw2/GHSA-7w9p-pr7x-mjw2.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-7w9p-pr7x-mjw2", - "modified": "2025-04-26T03:30:32Z", + "modified": "2025-05-02T15:31:16Z", "published": "2025-04-24T18:31:08Z", "aliases": [ "CVE-2025-31324" @@ -23,6 +23,10 @@ "type": "WEB", "url": "https://me.sap.com/notes/3594142" }, + { + "type": "WEB", + "url": "https://onapsis.com/blog/active-exploitation-of-sap-vulnerability-cve-2025-31324" + }, { "type": "WEB", "url": "https://url.sap/sapsecuritypatchday" diff --git a/advisories/unreviewed/2025/04/GHSA-fv83-m6v9-qw8v/GHSA-fv83-m6v9-qw8v.json b/advisories/unreviewed/2025/04/GHSA-fv83-m6v9-qw8v/GHSA-fv83-m6v9-qw8v.json index 40cd26e44ee..fe16cc3884d 100644 --- a/advisories/unreviewed/2025/04/GHSA-fv83-m6v9-qw8v/GHSA-fv83-m6v9-qw8v.json +++ b/advisories/unreviewed/2025/04/GHSA-fv83-m6v9-qw8v/GHSA-fv83-m6v9-qw8v.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-fv83-m6v9-qw8v", - "modified": "2025-04-30T18:31:56Z", + "modified": "2025-05-02T15:31:24Z", "published": "2025-04-30T18:31:56Z", "aliases": [ "CVE-2025-46619" ], "details": "A security issue has been discovered in Couchbase Server before 7.6.4 and fixed in v.7.6.4 and v.7.2.7 for Windows that could allow unauthorized access to sensitive files. Depending on the level of privileges, this vulnerability may grant access to files such as /etc/passwd or /etc/shadow.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-30T18:15:48Z" diff --git a/advisories/unreviewed/2025/04/GHSA-hf49-wfhj-98g5/GHSA-hf49-wfhj-98g5.json b/advisories/unreviewed/2025/04/GHSA-hf49-wfhj-98g5/GHSA-hf49-wfhj-98g5.json index 309bcaa3c4e..4bdc15fb66a 100644 --- a/advisories/unreviewed/2025/04/GHSA-hf49-wfhj-98g5/GHSA-hf49-wfhj-98g5.json +++ b/advisories/unreviewed/2025/04/GHSA-hf49-wfhj-98g5/GHSA-hf49-wfhj-98g5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hf49-wfhj-98g5", - "modified": "2025-04-30T18:31:56Z", + "modified": "2025-05-02T15:31:24Z", "published": "2025-04-30T18:31:55Z", "aliases": [ "CVE-2025-44194" ], "details": "SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_household.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-30T18:15:47Z" diff --git a/advisories/unreviewed/2025/04/GHSA-px62-fqwr-9g32/GHSA-px62-fqwr-9g32.json b/advisories/unreviewed/2025/04/GHSA-px62-fqwr-9g32/GHSA-px62-fqwr-9g32.json index 8f05da2aac9..2c63a6d6255 100644 --- a/advisories/unreviewed/2025/04/GHSA-px62-fqwr-9g32/GHSA-px62-fqwr-9g32.json +++ b/advisories/unreviewed/2025/04/GHSA-px62-fqwr-9g32/GHSA-px62-fqwr-9g32.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-px62-fqwr-9g32", - "modified": "2025-04-30T18:31:55Z", + "modified": "2025-05-02T15:31:23Z", "published": "2025-04-30T18:31:55Z", "aliases": [ "CVE-2025-44193" ], "details": "SourceCodester Simple Barangay Management System v1.0 has a SQL injection vulnerability in /barangay_management/admin/?page=view_complaint.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-04-30T18:15:47Z" diff --git a/advisories/unreviewed/2025/05/GHSA-235m-7f4x-p4m8/GHSA-235m-7f4x-p4m8.json b/advisories/unreviewed/2025/05/GHSA-235m-7f4x-p4m8/GHSA-235m-7f4x-p4m8.json new file mode 100644 index 00000000000..30e69883c9e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-235m-7f4x-p4m8/GHSA-235m-7f4x-p4m8.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-235m-7f4x-p4m8", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-44866" + ], + "details": "Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the level parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44866" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Tenda_W20E/formSetDebugCfg_level/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2954-4rrv-2pfp/GHSA-2954-4rrv-2pfp.json b/advisories/unreviewed/2025/05/GHSA-2954-4rrv-2pfp/GHSA-2954-4rrv-2pfp.json index a734ed5a1e8..915442f505f 100644 --- a/advisories/unreviewed/2025/05/GHSA-2954-4rrv-2pfp/GHSA-2954-4rrv-2pfp.json +++ b/advisories/unreviewed/2025/05/GHSA-2954-4rrv-2pfp/GHSA-2954-4rrv-2pfp.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-2954-4rrv-2pfp", - "modified": "2025-05-02T06:31:25Z", + "modified": "2025-05-02T15:31:47Z", "published": "2025-05-02T06:31:25Z", "aliases": [ "CVE-2025-3514" ], "details": "The SureForms WordPress plugin before 1.4.4 does not sanitise and escape some of its Form settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-02T06:15:48Z" diff --git a/advisories/unreviewed/2025/05/GHSA-2f49-8wxx-67mg/GHSA-2f49-8wxx-67mg.json b/advisories/unreviewed/2025/05/GHSA-2f49-8wxx-67mg/GHSA-2f49-8wxx-67mg.json new file mode 100644 index 00000000000..5a483d66e2c --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2f49-8wxx-67mg/GHSA-2f49-8wxx-67mg.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f49-8wxx-67mg", + "modified": "2025-05-02T15:31:48Z", + "published": "2025-05-02T15:31:48Z", + "aliases": [ + "CVE-2025-4204" + ], + "details": "The Ultimate Auction Pro plugin for WordPress is vulnerable to SQL Injection via the ‘auction_id’ parameter in all versions up to, and including, 1.5.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4204" + }, + { + "type": "WEB", + "url": "https://auctionplugin.net/changelog/ultimate-woo-auction-pro" + }, + { + "type": "WEB", + "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e492029d-6613-4881-b986-9fe14cb2cf74?source=cve" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-02T13:15:47Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2f6c-h568-c2f2/GHSA-2f6c-h568-c2f2.json b/advisories/unreviewed/2025/05/GHSA-2f6c-h568-c2f2/GHSA-2f6c-h568-c2f2.json new file mode 100644 index 00000000000..42245ee8911 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2f6c-h568-c2f2/GHSA-2f6c-h568-c2f2.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2f6c-h568-c2f2", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-35975" + ], + "details": "MicroDicom DICOM Viewer is vulnerable to an out-of-bounds write which may allow an attacker to execute arbitrary code. The user must open a malicious DCM file for exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-35975" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-121-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T19:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-2px4-35vj-j3x5/GHSA-2px4-35vj-j3x5.json b/advisories/unreviewed/2025/05/GHSA-2px4-35vj-j3x5/GHSA-2px4-35vj-j3x5.json new file mode 100644 index 00000000000..df90e0c6946 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-2px4-35vj-j3x5/GHSA-2px4-35vj-j3x5.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-2px4-35vj-j3x5", + "modified": "2025-05-02T15:31:44Z", + "published": "2025-05-02T15:31:44Z", + "aliases": [ + "CVE-2025-44861" + ], + "details": "TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44861" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Totolink_CA300-POE/CloudSrvUserdataVersionCheck/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-38h7-w62h-qf32/GHSA-38h7-w62h-qf32.json b/advisories/unreviewed/2025/05/GHSA-38h7-w62h-qf32/GHSA-38h7-w62h-qf32.json new file mode 100644 index 00000000000..68024f5c1d9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-38h7-w62h-qf32/GHSA-38h7-w62h-qf32.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38h7-w62h-qf32", + "modified": "2025-05-02T15:31:49Z", + "published": "2025-05-02T15:31:49Z", + "aliases": [ + "CVE-2025-44868" + ], + "details": "Wavlink WL-WN530H4 20220801 was found to contain a command injection vulnerability in the ping_test function of the adm.cgi via the pingIp parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44868" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Wavlink_WL-WN530H4/ping_test/readme.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-02T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-47r6-rvxr-w4cc/GHSA-47r6-rvxr-w4cc.json b/advisories/unreviewed/2025/05/GHSA-47r6-rvxr-w4cc/GHSA-47r6-rvxr-w4cc.json new file mode 100644 index 00000000000..4a047d73d2a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-47r6-rvxr-w4cc/GHSA-47r6-rvxr-w4cc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-47r6-rvxr-w4cc", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-44867" + ], + "details": "Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetNetCheckTools function via the hostName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44867" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Tenda_W20E/formSetNetCheckTools/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-4p7f-6rw5-m5v7/GHSA-4p7f-6rw5-m5v7.json b/advisories/unreviewed/2025/05/GHSA-4p7f-6rw5-m5v7/GHSA-4p7f-6rw5-m5v7.json new file mode 100644 index 00000000000..642f16366b1 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-4p7f-6rw5-m5v7/GHSA-4p7f-6rw5-m5v7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4p7f-6rw5-m5v7", + "modified": "2025-05-02T15:31:48Z", + "published": "2025-05-02T15:31:47Z", + "aliases": [ + "CVE-2025-2605" + ], + "details": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Honeywell MB-Secure allows Privilege Abuse. This issue affects MB-Secure: from V11.04 before V12.53 and MB-Secure PRO from V01.06 before V03.09.Honeywell also recommends updating to the most recent version of this product.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-2605" + }, + { + "type": "WEB", + "url": "https://www.honeywell.com/us/en/product-security#security-notices" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-02T13:15:46Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-54g8-pj2j-rgc7/GHSA-54g8-pj2j-rgc7.json b/advisories/unreviewed/2025/05/GHSA-54g8-pj2j-rgc7/GHSA-54g8-pj2j-rgc7.json new file mode 100644 index 00000000000..3a142ea16fc --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-54g8-pj2j-rgc7/GHSA-54g8-pj2j-rgc7.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-54g8-pj2j-rgc7", + "modified": "2025-05-02T15:31:44Z", + "published": "2025-05-02T15:31:44Z", + "aliases": [ + "CVE-2025-44860" + ], + "details": "TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Port parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44860" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Totolink_CA300-POE/msg_process_Port/readme.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-5gp3-3rvx-qhx2/GHSA-5gp3-3rvx-qhx2.json b/advisories/unreviewed/2025/05/GHSA-5gp3-3rvx-qhx2/GHSA-5gp3-3rvx-qhx2.json index fbe1b031d94..3d1e9e9b4d1 100644 --- a/advisories/unreviewed/2025/05/GHSA-5gp3-3rvx-qhx2/GHSA-5gp3-3rvx-qhx2.json +++ b/advisories/unreviewed/2025/05/GHSA-5gp3-3rvx-qhx2/GHSA-5gp3-3rvx-qhx2.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-5gp3-3rvx-qhx2", - "modified": "2025-05-01T06:30:28Z", + "modified": "2025-05-02T15:31:26Z", "published": "2025-05-01T06:30:28Z", "aliases": [ "CVE-2024-13381" ], "details": "The Calculated Fields Form WordPress plugin before 5.2.62 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N" + } + ], "affected": [], "references": [ { @@ -21,7 +26,7 @@ ], "database_specific": { "cwe_ids": [], - "severity": null, + "severity": "LOW", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-01T06:15:33Z" diff --git a/advisories/unreviewed/2025/05/GHSA-629x-6x88-9g8p/GHSA-629x-6x88-9g8p.json b/advisories/unreviewed/2025/05/GHSA-629x-6x88-9g8p/GHSA-629x-6x88-9g8p.json new file mode 100644 index 00000000000..9af6d7936db --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-629x-6x88-9g8p/GHSA-629x-6x88-9g8p.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-629x-6x88-9g8p", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-32011" + ], + "details": "KUNBUS PiCtory versions 2.5.0 through 2.11.1 have an authentication bypass vulnerability where a remote attacker can bypass authentication to get access due to a path traversal.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32011" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-121-01" + }, + { + "type": "WEB", + "url": "http://packages.revolutionpi.de/pool/main/p/pictory" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-305" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T19:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6337-gf92-4pxh/GHSA-6337-gf92-4pxh.json b/advisories/unreviewed/2025/05/GHSA-6337-gf92-4pxh/GHSA-6337-gf92-4pxh.json new file mode 100644 index 00000000000..55b20170d92 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6337-gf92-4pxh/GHSA-6337-gf92-4pxh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6337-gf92-4pxh", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-44865" + ], + "details": "Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the enable parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44865" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Tenda_W20E/formSetDebugCfg_enable/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T18:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6c7x-4pvf-q257/GHSA-6c7x-4pvf-q257.json b/advisories/unreviewed/2025/05/GHSA-6c7x-4pvf-q257/GHSA-6c7x-4pvf-q257.json new file mode 100644 index 00000000000..50fcde75724 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6c7x-4pvf-q257/GHSA-6c7x-4pvf-q257.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6c7x-4pvf-q257", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:44Z", + "aliases": [ + "CVE-2025-44863" + ], + "details": "TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the msg_process function via the Url parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44863" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Totolink_CA300-POE/msg_process_Url/readme.md" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-6jfm-gw74-r7cx/GHSA-6jfm-gw74-r7cx.json b/advisories/unreviewed/2025/05/GHSA-6jfm-gw74-r7cx/GHSA-6jfm-gw74-r7cx.json index ac7456ea62f..ce71f69a81d 100644 --- a/advisories/unreviewed/2025/05/GHSA-6jfm-gw74-r7cx/GHSA-6jfm-gw74-r7cx.json +++ b/advisories/unreviewed/2025/05/GHSA-6jfm-gw74-r7cx/GHSA-6jfm-gw74-r7cx.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6jfm-gw74-r7cx", - "modified": "2025-05-02T03:30:35Z", + "modified": "2025-05-02T15:31:46Z", "published": "2025-05-02T03:30:34Z", "aliases": [ "CVE-2025-4193" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://github.com/ARPANET-cybersecurity/vuldb/issues/5" }, + { + "type": "WEB", + "url": "https://github.com/XuepengZhao-insp/vuldb/issues/5" + }, { "type": "WEB", "url": "https://itsourcecode.com" diff --git a/advisories/unreviewed/2025/05/GHSA-6jw2-2v2j-w474/GHSA-6jw2-2v2j-w474.json b/advisories/unreviewed/2025/05/GHSA-6jw2-2v2j-w474/GHSA-6jw2-2v2j-w474.json new file mode 100644 index 00000000000..7b532d81f75 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-6jw2-2v2j-w474/GHSA-6jw2-2v2j-w474.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6jw2-2v2j-w474", + "modified": "2025-05-02T15:31:49Z", + "published": "2025-05-02T15:31:49Z", + "aliases": [ + "CVE-2025-44872" + ], + "details": "Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formsetUsbUnload function via the deviceName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44872" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Tenda_AC/AC9_formsetUsbUnload" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-02T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-84vm-w284-7p68/GHSA-84vm-w284-7p68.json b/advisories/unreviewed/2025/05/GHSA-84vm-w284-7p68/GHSA-84vm-w284-7p68.json new file mode 100644 index 00000000000..3feaa55e3ab --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-84vm-w284-7p68/GHSA-84vm-w284-7p68.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-84vm-w284-7p68", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-36558" + ], + "details": "KUNBUS PiCtory version 2.11.1 and earlier are vulnerable to a cross-site-scripting attack via the sso_token used for authentication. If an attacker provides the user with a PiCtory URL containing an HTML script as an sso_token, that script will reply to the user and be executed.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-36558" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-121-01" + }, + { + "type": "WEB", + "url": "http://packages.revolutionpi.de/pool/main/p/pictory" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-97" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T19:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8c5w-f239-2ghg/GHSA-8c5w-f239-2ghg.json b/advisories/unreviewed/2025/05/GHSA-8c5w-f239-2ghg/GHSA-8c5w-f239-2ghg.json new file mode 100644 index 00000000000..a600e2f1df5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8c5w-f239-2ghg/GHSA-8c5w-f239-2ghg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8c5w-f239-2ghg", + "modified": "2025-05-02T15:31:48Z", + "published": "2025-05-02T15:31:48Z", + "aliases": [ + "CVE-2025-1884" + ], + "details": "Use-After-Free vulnerability exists in the SLDPRT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted SLDPRT file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1884" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-02T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-8gr9-8p2v-p75h/GHSA-8gr9-8p2v-p75h.json b/advisories/unreviewed/2025/05/GHSA-8gr9-8p2v-p75h/GHSA-8gr9-8p2v-p75h.json index 41c215fad25..57735d8e3da 100644 --- a/advisories/unreviewed/2025/05/GHSA-8gr9-8p2v-p75h/GHSA-8gr9-8p2v-p75h.json +++ b/advisories/unreviewed/2025/05/GHSA-8gr9-8p2v-p75h/GHSA-8gr9-8p2v-p75h.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-8gr9-8p2v-p75h", - "modified": "2025-05-01T15:31:45Z", + "modified": "2025-05-02T15:31:34Z", "published": "2025-05-01T15:31:45Z", "aliases": [ "CVE-2025-44835" ], "details": "D-Link DIR-816 A2V1.1.0B05 was found to contain a command injection in iptablesWebsFilterRun, which allows remote attackers to execute arbitrary commands via shell.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-01T14:15:45Z" diff --git a/advisories/unreviewed/2025/05/GHSA-8p7h-p6p4-gqfw/GHSA-8p7h-p6p4-gqfw.json b/advisories/unreviewed/2025/05/GHSA-8p7h-p6p4-gqfw/GHSA-8p7h-p6p4-gqfw.json new file mode 100644 index 00000000000..c13da4bd5a6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-8p7h-p6p4-gqfw/GHSA-8p7h-p6p4-gqfw.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8p7h-p6p4-gqfw", + "modified": "2025-05-02T15:31:43Z", + "published": "2025-05-02T15:31:43Z", + "aliases": [ + "CVE-2025-32883" + ], + "details": "An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. The app there makes it possible to inject any custom message (into existing mesh networks) with any GID and Callsign via a software defined radio. This can be exploited if the device is being used in an unencrypted environment or if the cryptography has already been compromised.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32883" + }, + { + "type": "WEB", + "url": "https://github.com/Dollarhyde/goTenna_v1_and_Mesh_vulnerabilities" + }, + { + "type": "WEB", + "url": "https://gotenna.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-923h-v2w5-rh8q/GHSA-923h-v2w5-rh8q.json b/advisories/unreviewed/2025/05/GHSA-923h-v2w5-rh8q/GHSA-923h-v2w5-rh8q.json new file mode 100644 index 00000000000..23e692cf806 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-923h-v2w5-rh8q/GHSA-923h-v2w5-rh8q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-923h-v2w5-rh8q", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-46630" + ], + "details": "Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable 'ate' (a remote system management binary) by sending a /goform/ate web request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46630" + }, + { + "type": "WEB", + "url": "https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46630-enable-ate-unauthenticated-through-httpd" + }, + { + "type": "WEB", + "url": "https://www.tendacn.com/us/default.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9cgq-h66g-4xhp/GHSA-9cgq-h66g-4xhp.json b/advisories/unreviewed/2025/05/GHSA-9cgq-h66g-4xhp/GHSA-9cgq-h66g-4xhp.json new file mode 100644 index 00000000000..02d94271b7d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9cgq-h66g-4xhp/GHSA-9cgq-h66g-4xhp.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9cgq-h66g-4xhp", + "modified": "2025-05-02T15:31:42Z", + "published": "2025-05-02T15:31:42Z", + "aliases": [ + "CVE-2025-32881" + ], + "details": "An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. By default, the GID is the user's phone number unless they specifically opt out. A phone number is very sensitive information because it can be tied back to individuals. The app does not encrypt the GID in messages.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32881" + }, + { + "type": "WEB", + "url": "https://github.com/Dollarhyde/goTenna_v1_and_Mesh_vulnerabilities" + }, + { + "type": "WEB", + "url": "https://gotenna.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T18:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9mp8-vffv-mgvx/GHSA-9mp8-vffv-mgvx.json b/advisories/unreviewed/2025/05/GHSA-9mp8-vffv-mgvx/GHSA-9mp8-vffv-mgvx.json new file mode 100644 index 00000000000..4eb5c5327e5 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9mp8-vffv-mgvx/GHSA-9mp8-vffv-mgvx.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9mp8-vffv-mgvx", + "modified": "2025-05-02T15:31:46Z", + "published": "2025-05-02T15:31:46Z", + "aliases": [ + "CVE-2024-48905" + ], + "details": "Sematell ReplyOne 7.4.3.0 has Insecure Permissions for the /rest/sessions endpoint.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48905" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-082.txt" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T21:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-9rr5-mrc9-96h4/GHSA-9rr5-mrc9-96h4.json b/advisories/unreviewed/2025/05/GHSA-9rr5-mrc9-96h4/GHSA-9rr5-mrc9-96h4.json new file mode 100644 index 00000000000..3cc643cbbe8 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-9rr5-mrc9-96h4/GHSA-9rr5-mrc9-96h4.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-9rr5-mrc9-96h4", + "modified": "2025-05-02T15:31:44Z", + "published": "2025-05-02T15:31:44Z", + "aliases": [ + "CVE-2025-32884" + ], + "details": "An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. By default, a GID is the user's phone number unless they specifically opt out. A phone number is very sensitive information because it can be tied back to individuals. The app does not encrypt the GID in messages.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32884" + }, + { + "type": "WEB", + "url": "https://github.com/Dollarhyde/goTenna_v1_and_Mesh_vulnerabilities" + }, + { + "type": "WEB", + "url": "https://gotenna.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-c89r-xwv9-fq4w/GHSA-c89r-xwv9-fq4w.json b/advisories/unreviewed/2025/05/GHSA-c89r-xwv9-fq4w/GHSA-c89r-xwv9-fq4w.json index 3589c796051..afc50edc0b2 100644 --- a/advisories/unreviewed/2025/05/GHSA-c89r-xwv9-fq4w/GHSA-c89r-xwv9-fq4w.json +++ b/advisories/unreviewed/2025/05/GHSA-c89r-xwv9-fq4w/GHSA-c89r-xwv9-fq4w.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-c89r-xwv9-fq4w", - "modified": "2025-05-01T15:31:45Z", + "modified": "2025-05-02T15:31:34Z", "published": "2025-05-01T15:31:45Z", "aliases": [ "CVE-2025-44854" ], "details": "Totolink CP900 V6.3c.1144_B20190715 was found to contain a command injection vulnerability in the setUpgradeUboot function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-01T14:15:45Z" diff --git a/advisories/unreviewed/2025/05/GHSA-cm8f-5fx7-mv6c/GHSA-cm8f-5fx7-mv6c.json b/advisories/unreviewed/2025/05/GHSA-cm8f-5fx7-mv6c/GHSA-cm8f-5fx7-mv6c.json new file mode 100644 index 00000000000..861285bdaa7 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-cm8f-5fx7-mv6c/GHSA-cm8f-5fx7-mv6c.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cm8f-5fx7-mv6c", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-36521" + ], + "details": "MicroDicom DICOM Viewer is vulnerable to an out-of-bounds read which may allow an attacker to cause memory corruption within the application. The user must open a malicious DCM file for exploitation.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-36521" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-121-01" + }, + { + "type": "WEB", + "url": "https://www.microdicom.com/downloads.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-125" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T19:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f57c-fm3p-ggmf/GHSA-f57c-fm3p-ggmf.json b/advisories/unreviewed/2025/05/GHSA-f57c-fm3p-ggmf/GHSA-f57c-fm3p-ggmf.json new file mode 100644 index 00000000000..e5072ea477b --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f57c-fm3p-ggmf/GHSA-f57c-fm3p-ggmf.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f57c-fm3p-ggmf", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-46629" + ], + "details": "Lack of access controls in the 'ate' management binary of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to perform unauthorized configuration changes for any router where 'ate' has been enabled by sending a crafted UDP packet", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46629" + }, + { + "type": "WEB", + "url": "https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46629-lack-of-authentication-in-ate" + }, + { + "type": "WEB", + "url": "https://www.tendacn.com/us/default.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-f5qp-wfgr-pm73/GHSA-f5qp-wfgr-pm73.json b/advisories/unreviewed/2025/05/GHSA-f5qp-wfgr-pm73/GHSA-f5qp-wfgr-pm73.json new file mode 100644 index 00000000000..eca56ccf751 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-f5qp-wfgr-pm73/GHSA-f5qp-wfgr-pm73.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-f5qp-wfgr-pm73", + "modified": "2025-05-02T15:31:44Z", + "published": "2025-05-02T15:31:44Z", + "aliases": [ + "CVE-2025-32885" + ], + "details": "An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app there makes it possible to inject any custom message (into existing v1 networks) with any GID and Callsign via a software defined radio. This can be exploited if the device is being used in an unencrypted environment or if the cryptography has already been compromised.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32885" + }, + { + "type": "WEB", + "url": "https://github.com/Dollarhyde/goTenna_v1_and_Mesh_vulnerabilities" + }, + { + "type": "WEB", + "url": "https://gotenna.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-1390" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-fgj7-v5cr-wfmr/GHSA-fgj7-v5cr-wfmr.json b/advisories/unreviewed/2025/05/GHSA-fgj7-v5cr-wfmr/GHSA-fgj7-v5cr-wfmr.json new file mode 100644 index 00000000000..ad3b95d292e --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-fgj7-v5cr-wfmr/GHSA-fgj7-v5cr-wfmr.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-fgj7-v5cr-wfmr", + "modified": "2025-05-02T15:31:43Z", + "published": "2025-05-02T15:31:43Z", + "aliases": [ + "CVE-2025-32882" + ], + "details": "An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The app uses a custom implementation of encryption without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32882" + }, + { + "type": "WEB", + "url": "https://github.com/Dollarhyde/goTenna_v1_and_Mesh_vulnerabilities" + }, + { + "type": "WEB", + "url": "https://gotenna.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-353" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gc4p-7qxx-hhrw/GHSA-gc4p-7qxx-hhrw.json b/advisories/unreviewed/2025/05/GHSA-gc4p-7qxx-hhrw/GHSA-gc4p-7qxx-hhrw.json new file mode 100644 index 00000000000..795f1ba2d93 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gc4p-7qxx-hhrw/GHSA-gc4p-7qxx-hhrw.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gc4p-7qxx-hhrw", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-46626" + ], + "details": "Reuse of a static AES key and initialization vector for encrypted traffic to the 'ate' management service of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt, replay, and/or forge traffic to the service.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46626" + }, + { + "type": "WEB", + "url": "https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46625-command-injection-through-setlancfg-in-httpd" + }, + { + "type": "WEB", + "url": "https://www.tendacn.com/us/default.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gcqf-f89c-68hv/GHSA-gcqf-f89c-68hv.json b/advisories/unreviewed/2025/05/GHSA-gcqf-f89c-68hv/GHSA-gcqf-f89c-68hv.json new file mode 100644 index 00000000000..cb471d4ae4d --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gcqf-f89c-68hv/GHSA-gcqf-f89c-68hv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcqf-f89c-68hv", + "modified": "2025-05-02T15:31:49Z", + "published": "2025-05-02T15:31:49Z", + "aliases": [ + "CVE-2025-4166" + ], + "details": "Vault Community and Vault Enterprise Key/Value (kv) Version 2 plugin may unintentionally expose sensitive information in server and audit logs when users submit malformed payloads during secret creation or update operations via the Vault REST API. This vulnerability, identified as CVE-2025-4166, is fixed in Vault Community 1.19.3 and Vault Enterprise 1.19.3, 1.18.9, 1.17.16, 1.16.20.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4166" + }, + { + "type": "WEB", + "url": "https://discuss.hashicorp.com/t/hcsec-2025-09-vault-may-expose-sensitive-information-in-error-logs-when-processing-malformed-data-with-the-kv-v2-plugin" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-209" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-02T15:15:50Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gcrr-4ph4-qm58/GHSA-gcrr-4ph4-qm58.json b/advisories/unreviewed/2025/05/GHSA-gcrr-4ph4-qm58/GHSA-gcrr-4ph4-qm58.json new file mode 100644 index 00000000000..857e947e0a6 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gcrr-4ph4-qm58/GHSA-gcrr-4ph4-qm58.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gcrr-4ph4-qm58", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-46628" + ], + "details": "Lack of input validation/sanitization in the 'ate' management service in the Tenda RX2 Pro 16.03.30.14 allows an unauthorized remote attacker to gain root shell access to the device by sending a crafted UDP packet to the 'ate' service when it is enabled. Authentication is not needed.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46628" + }, + { + "type": "WEB", + "url": "https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46628-command-injection-through-ifconfig-command-in-ate" + }, + { + "type": "WEB", + "url": "https://www.tendacn.com/us/default.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-gwq8-8443-vx69/GHSA-gwq8-8443-vx69.json b/advisories/unreviewed/2025/05/GHSA-gwq8-8443-vx69/GHSA-gwq8-8443-vx69.json new file mode 100644 index 00000000000..de1fe0e2b67 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-gwq8-8443-vx69/GHSA-gwq8-8443-vx69.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-gwq8-8443-vx69", + "modified": "2025-05-02T15:31:46Z", + "published": "2025-05-02T15:31:46Z", + "aliases": [ + "CVE-2024-48906" + ], + "details": "Sematell ReplyOne 7.4.3.0 allows XSS via a ReplyDesk e-mail attachment name.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48906" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-081.txt" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T21:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hpgq-64pq-cxw5/GHSA-hpgq-64pq-cxw5.json b/advisories/unreviewed/2025/05/GHSA-hpgq-64pq-cxw5/GHSA-hpgq-64pq-cxw5.json index 5101749ada3..2c9cdc3eb49 100644 --- a/advisories/unreviewed/2025/05/GHSA-hpgq-64pq-cxw5/GHSA-hpgq-64pq-cxw5.json +++ b/advisories/unreviewed/2025/05/GHSA-hpgq-64pq-cxw5/GHSA-hpgq-64pq-cxw5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hpgq-64pq-cxw5", - "modified": "2025-05-01T15:31:53Z", + "modified": "2025-05-02T15:31:41Z", "published": "2025-05-01T15:31:53Z", "aliases": [ "CVE-2025-44836" ], "details": "TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setApRebootScheCfg function via the hour or minute parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-01T15:16:20Z" diff --git a/advisories/unreviewed/2025/05/GHSA-hrj3-q54c-3v45/GHSA-hrj3-q54c-3v45.json b/advisories/unreviewed/2025/05/GHSA-hrj3-q54c-3v45/GHSA-hrj3-q54c-3v45.json new file mode 100644 index 00000000000..2211a5753d2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hrj3-q54c-3v45/GHSA-hrj3-q54c-3v45.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hrj3-q54c-3v45", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-44864" + ], + "details": "Tenda W20E V15.11.0.6 was found to contain a command injection vulnerability in the formSetDebugCfg function via the module parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44864" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Tenda_W20E/formSetDebugCfg_module/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hvr4-ppmm-c7fp/GHSA-hvr4-ppmm-c7fp.json b/advisories/unreviewed/2025/05/GHSA-hvr4-ppmm-c7fp/GHSA-hvr4-ppmm-c7fp.json new file mode 100644 index 00000000000..1cf29fc7641 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-hvr4-ppmm-c7fp/GHSA-hvr4-ppmm-c7fp.json @@ -0,0 +1,57 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvr4-ppmm-c7fp", + "modified": "2025-05-02T15:31:48Z", + "published": "2025-05-02T15:31:48Z", + "aliases": [ + "CVE-2025-37797" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\nnet_sched: hfsc: Fix a UAF vulnerability in class handling\n\nThis patch fixes a Use-After-Free vulnerability in the HFSC qdisc class\nhandling. The issue occurs due to a time-of-check/time-of-use condition\nin hfsc_change_class() when working with certain child qdiscs like netem\nor codel.\n\nThe vulnerability works as follows:\n1. hfsc_change_class() checks if a class has packets (q.qlen != 0)\n2. It then calls qdisc_peek_len(), which for certain qdiscs (e.g.,\n codel, netem) might drop packets and empty the queue\n3. The code continues assuming the queue is still non-empty, adding\n the class to vttree\n4. This breaks HFSC scheduler assumptions that only non-empty classes\n are in vttree\n5. Later, when the class is destroyed, this can lead to a Use-After-Free\n\nThe fix adds a second queue length check after qdisc_peek_len() to verify\nthe queue wasn't emptied.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37797" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/20d584a33e480ae80d105f43e0e7b56784da41b9" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/28b09a067831f7317c3841812276022d6c940677" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/39b9095dd3b55d9b2743df038c32138efa34a9de" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3aa852e3605000d5c47035c3fc3a986d14ccfa9f" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/3df275ef0a6ae181e8428a6589ef5d5231e58b5c" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/86cd4641c713455a4f1c8e54c370c598c2b1cee0" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/bb583c88d23b72d8d16453d24856c99bd93dadf5" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/fcc8ede663569c704fb00a702973bd6c00373283" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-02T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-hx3p-h798-3rh6/GHSA-hx3p-h798-3rh6.json b/advisories/unreviewed/2025/05/GHSA-hx3p-h798-3rh6/GHSA-hx3p-h798-3rh6.json index b8c225a5cbe..093a71d50b0 100644 --- a/advisories/unreviewed/2025/05/GHSA-hx3p-h798-3rh6/GHSA-hx3p-h798-3rh6.json +++ b/advisories/unreviewed/2025/05/GHSA-hx3p-h798-3rh6/GHSA-hx3p-h798-3rh6.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-hx3p-h798-3rh6", - "modified": "2025-05-01T18:31:47Z", + "modified": "2025-05-02T15:31:41Z", "published": "2025-05-01T18:31:47Z", "aliases": [ "CVE-2025-44846" ], "details": "TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-01T17:15:50Z" diff --git a/advisories/unreviewed/2025/05/GHSA-j4xm-9jmh-g7cv/GHSA-j4xm-9jmh-g7cv.json b/advisories/unreviewed/2025/05/GHSA-j4xm-9jmh-g7cv/GHSA-j4xm-9jmh-g7cv.json new file mode 100644 index 00000000000..700e713e8a3 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-j4xm-9jmh-g7cv/GHSA-j4xm-9jmh-g7cv.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j4xm-9jmh-g7cv", + "modified": "2025-05-02T15:31:44Z", + "published": "2025-05-02T15:31:44Z", + "aliases": [ + "CVE-2025-32889" + ], + "details": "An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. The verification token used for sending SMS through a goTenna server is hardcoded in the app.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32889" + }, + { + "type": "WEB", + "url": "https://github.com/Dollarhyde/goTenna_v1_and_Mesh_vulnerabilities" + }, + { + "type": "WEB", + "url": "https://gotenna.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-jqgh-w22q-m24f/GHSA-jqgh-w22q-m24f.json b/advisories/unreviewed/2025/05/GHSA-jqgh-w22q-m24f/GHSA-jqgh-w22q-m24f.json new file mode 100644 index 00000000000..81f0b24a068 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-jqgh-w22q-m24f/GHSA-jqgh-w22q-m24f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jqgh-w22q-m24f", + "modified": "2025-05-02T15:31:44Z", + "published": "2025-05-02T15:31:44Z", + "aliases": [ + "CVE-2025-32888" + ], + "details": "An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. The verification token used for sending SMS through a goTenna server is hardcoded in the app.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32888" + }, + { + "type": "WEB", + "url": "https://github.com/Dollarhyde/goTenna_v1_and_Mesh_vulnerabilities" + }, + { + "type": "WEB", + "url": "https://gotenna.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-798" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mq93-f783-wcgv/GHSA-mq93-f783-wcgv.json b/advisories/unreviewed/2025/05/GHSA-mq93-f783-wcgv/GHSA-mq93-f783-wcgv.json new file mode 100644 index 00000000000..4beaee848d4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mq93-f783-wcgv/GHSA-mq93-f783-wcgv.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mq93-f783-wcgv", + "modified": "2025-05-02T15:31:44Z", + "published": "2025-05-02T15:31:44Z", + "aliases": [ + "CVE-2025-44862" + ], + "details": "TOTOLINK CA300-POE V6.2c.884_B20180522 was found to contain a command injection vulnerability in the recvUpgradeNewFw function via the fwUrl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44862" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Totolink_CA300-POE/recvUpgradeNewFw/readme.md" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-mv7w-j26m-h74p/GHSA-mv7w-j26m-h74p.json b/advisories/unreviewed/2025/05/GHSA-mv7w-j26m-h74p/GHSA-mv7w-j26m-h74p.json new file mode 100644 index 00000000000..d05a68b09aa --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-mv7w-j26m-h74p/GHSA-mv7w-j26m-h74p.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mv7w-j26m-h74p", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-24522" + ], + "details": "KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server where they can run arbitrary commands on the underlying operating system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-24522" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-121-01" + }, + { + "type": "WEB", + "url": "http://packages.revolutionpi.de/pool/main/p/pictory" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-305" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T19:15:57Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p3h7-jggj-frv4/GHSA-p3h7-jggj-frv4.json b/advisories/unreviewed/2025/05/GHSA-p3h7-jggj-frv4/GHSA-p3h7-jggj-frv4.json new file mode 100644 index 00000000000..31007a83d2a --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-p3h7-jggj-frv4/GHSA-p3h7-jggj-frv4.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p3h7-jggj-frv4", + "modified": "2025-05-02T15:31:49Z", + "published": "2025-05-02T15:31:49Z", + "aliases": [ + "CVE-2025-44877" + ], + "details": "Tenda AC9 V15.03.06.42_multi was found to contain a command injection vulnerability in the formSetSambaConf function via the usbname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-44877" + }, + { + "type": "WEB", + "url": "https://github.com/Summermu/VulnForIoT/tree/main/Tenda_AC/AC9_formSetSambaConf" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-02T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-p474-6pr8-pwcj/GHSA-p474-6pr8-pwcj.json b/advisories/unreviewed/2025/05/GHSA-p474-6pr8-pwcj/GHSA-p474-6pr8-pwcj.json index 247f08afaf8..1acb51f5a10 100644 --- a/advisories/unreviewed/2025/05/GHSA-p474-6pr8-pwcj/GHSA-p474-6pr8-pwcj.json +++ b/advisories/unreviewed/2025/05/GHSA-p474-6pr8-pwcj/GHSA-p474-6pr8-pwcj.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-p474-6pr8-pwcj", - "modified": "2025-05-02T03:30:34Z", + "modified": "2025-05-02T15:31:46Z", "published": "2025-05-02T03:30:34Z", "aliases": [ "CVE-2025-4192" @@ -27,6 +27,10 @@ "type": "WEB", "url": "https://github.com/ARPANET-cybersecurity/vuldb/issues/4" }, + { + "type": "WEB", + "url": "https://github.com/XuepengZhao-insp/vuldb/issues/4" + }, { "type": "WEB", "url": "https://itsourcecode.com" diff --git a/advisories/unreviewed/2025/05/GHSA-pf87-p9pq-44q4/GHSA-pf87-p9pq-44q4.json b/advisories/unreviewed/2025/05/GHSA-pf87-p9pq-44q4/GHSA-pf87-p9pq-44q4.json new file mode 100644 index 00000000000..397a8ac6616 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pf87-p9pq-44q4/GHSA-pf87-p9pq-44q4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pf87-p9pq-44q4", + "modified": "2025-05-02T15:31:46Z", + "published": "2025-05-02T15:31:46Z", + "aliases": [ + "CVE-2024-48907" + ], + "details": "Sematell ReplyOne 7.4.3.0 allows SSRF via the application server API.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-48907" + }, + { + "type": "WEB", + "url": "https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2024-083.txt" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-918" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T21:15:52Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pjhx-jp78-8pv5/GHSA-pjhx-jp78-8pv5.json b/advisories/unreviewed/2025/05/GHSA-pjhx-jp78-8pv5/GHSA-pjhx-jp78-8pv5.json new file mode 100644 index 00000000000..e034fcfe3be --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pjhx-jp78-8pv5/GHSA-pjhx-jp78-8pv5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pjhx-jp78-8pv5", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-46633" + ], + "details": "Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an attacker to decrypt traffic between the client and server by collecting the symmetric AES key from collected and/or observed traffic. The AES key in sent in cleartext in response to successful authentication. The IV is always EU5H62G9ICGRNI43.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46633" + }, + { + "type": "WEB", + "url": "https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46633-transmission-of-plaintext-symmetric-key-in-httpd" + }, + { + "type": "WEB", + "url": "https://www.tendacn.com/us/default.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-pm2w-vj7f-h667/GHSA-pm2w-vj7f-h667.json b/advisories/unreviewed/2025/05/GHSA-pm2w-vj7f-h667/GHSA-pm2w-vj7f-h667.json new file mode 100644 index 00000000000..fc47369b18f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-pm2w-vj7f-h667/GHSA-pm2w-vj7f-h667.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pm2w-vj7f-h667", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-46634" + ], + "details": "Cleartext transmission of sensitive information in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an unauthenticated attacker to authenticate to the web management portal by collecting credentials from observed/collected traffic. It implements encryption, but not until after the user has transmitted the hash of their password in cleartext. The hash can be replayed to authenticate.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46634" + }, + { + "type": "WEB", + "url": "https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46634-transmission-of-plaintext-credentials-in-httpd" + }, + { + "type": "WEB", + "url": "https://www.tendacn.com/us/default.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-312" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-ppc7-gq7r-hvm6/GHSA-ppc7-gq7r-hvm6.json b/advisories/unreviewed/2025/05/GHSA-ppc7-gq7r-hvm6/GHSA-ppc7-gq7r-hvm6.json new file mode 100644 index 00000000000..91b4e2bb674 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-ppc7-gq7r-hvm6/GHSA-ppc7-gq7r-hvm6.json @@ -0,0 +1,52 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-ppc7-gq7r-hvm6", + "modified": "2025-05-02T15:31:46Z", + "published": "2025-05-02T15:31:46Z", + "aliases": [ + "CVE-2025-4175" + ], + "details": "A vulnerability, which was classified as critical, was found in AlanBinu007 Spring-Boot-Advanced-Projects up to 3.1.3. This affects the function uploadUserProfileImage of the file /Spring-Boot-Advanced-Projects-main/Project-4.SpringBoot-AWS-S3/backend/src/main/java/com/urunov/profile/UserProfileController.jav of the component Upload Profile API Endpoint. The manipulation of the argument File leads to path traversal. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4175" + }, + { + "type": "WEB", + "url": "https://github.com/ShenxiuSec/cve-proofs/blob/main/POC-20250418-01.md" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306795" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306795" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.561760" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T21:15:54Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q25g-m88j-xmgx/GHSA-q25g-m88j-xmgx.json b/advisories/unreviewed/2025/05/GHSA-q25g-m88j-xmgx/GHSA-q25g-m88j-xmgx.json new file mode 100644 index 00000000000..ecebfa3d167 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-q25g-m88j-xmgx/GHSA-q25g-m88j-xmgx.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-q25g-m88j-xmgx", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-46625" + ], + "details": "Lack of input validation/sanitization in the 'setLanCfg' API endpoint in httpd in the Tenda RX2 Pro 16.03.30.14 allows a remote attacker that is authorized to the web management portal to gain root shell access to the device by sending a crafted web request. This is persistent because the command injection is saved in the configuration of the device.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46625" + }, + { + "type": "WEB", + "url": "https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46625-command-injection-through-setlancfg-in-httpd" + }, + { + "type": "WEB", + "url": "https://www.tendacn.com/us/default.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-77" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-q7v8-cc74-49m7/GHSA-q7v8-cc74-49m7.json b/advisories/unreviewed/2025/05/GHSA-q7v8-cc74-49m7/GHSA-q7v8-cc74-49m7.json index e4e404a6ca9..eef9b135309 100644 --- a/advisories/unreviewed/2025/05/GHSA-q7v8-cc74-49m7/GHSA-q7v8-cc74-49m7.json +++ b/advisories/unreviewed/2025/05/GHSA-q7v8-cc74-49m7/GHSA-q7v8-cc74-49m7.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-q7v8-cc74-49m7", - "modified": "2025-05-01T15:31:53Z", + "modified": "2025-05-02T15:31:41Z", "published": "2025-05-01T15:31:53Z", "aliases": [ "CVE-2025-44838" ], "details": "TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the setUploadUserData function via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-01T15:16:20Z" diff --git a/advisories/unreviewed/2025/05/GHSA-qfpx-fgcv-pjx6/GHSA-qfpx-fgcv-pjx6.json b/advisories/unreviewed/2025/05/GHSA-qfpx-fgcv-pjx6/GHSA-qfpx-fgcv-pjx6.json new file mode 100644 index 00000000000..76cf08ad032 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qfpx-fgcv-pjx6/GHSA-qfpx-fgcv-pjx6.json @@ -0,0 +1,49 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qfpx-fgcv-pjx6", + "modified": "2025-05-02T15:31:48Z", + "published": "2025-05-02T15:31:48Z", + "aliases": [ + "CVE-2025-37798" + ], + "details": "In the Linux kernel, the following vulnerability has been resolved:\n\ncodel: remove sch->q.qlen check before qdisc_tree_reduce_backlog()\n\nAfter making all ->qlen_notify() callbacks idempotent, now it is safe to\nremove the check of qlen!=0 from both fq_codel_dequeue() and\ncodel_qdisc_dequeue().", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-37798" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/2f9761a94bae33d26e6a81b31b36e7d776d93dc1" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/342debc12183b51773b3345ba267e9263bdfaaef" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/4d55144b12e742404bb3f8fee6038bafbf45619d" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/829c49b6b2ff45b043739168fd1245e4e1a91a30" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/a57fe60ef4cf96bfbb6b58397ec28bdb5a5c6b31" + }, + { + "type": "WEB", + "url": "https://git.kernel.org/stable/c/e73c838c80dccb9e4f19becc11d9f3cb4a27d483" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-02T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qmqc-h5gj-qcf5/GHSA-qmqc-h5gj-qcf5.json b/advisories/unreviewed/2025/05/GHSA-qmqc-h5gj-qcf5/GHSA-qmqc-h5gj-qcf5.json new file mode 100644 index 00000000000..e42262626ae --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qmqc-h5gj-qcf5/GHSA-qmqc-h5gj-qcf5.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qmqc-h5gj-qcf5", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-46635" + ], + "details": "An issue was discovered on Tenda RX2 Pro 16.03.30.14 devices. Improper network isolation between the guest Wi-Fi network and other network interfaces on the router allows an attacker (who is authenticated to the guest Wi-Fi) to access resources on the router and/or resources and devices on other networks hosted by the router by configuring a static IP address (within the non-guest subnet) on their host.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46635" + }, + { + "type": "WEB", + "url": "https://blog.uturn.dev/#/writeups/iot-village/tenda-w18e/README?id=cve-2024-46435-delfacebookpic-stack-overflow" + }, + { + "type": "WEB", + "url": "https://www.tendacn.com/us/default.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-284" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qph7-xc8r-fqmj/GHSA-qph7-xc8r-fqmj.json b/advisories/unreviewed/2025/05/GHSA-qph7-xc8r-fqmj/GHSA-qph7-xc8r-fqmj.json new file mode 100644 index 00000000000..568dd98a286 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qph7-xc8r-fqmj/GHSA-qph7-xc8r-fqmj.json @@ -0,0 +1,29 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qph7-xc8r-fqmj", + "modified": "2025-05-02T15:31:48Z", + "published": "2025-05-02T15:31:48Z", + "aliases": [ + "CVE-2025-3927" + ], + "details": "Digigram's PYKO-OUT audio-over-IP (AoIP) web-server does not require a password by default, allowing any attacker with the target IP address to connect and compromise the device, potentially pivoting to connected network or hardware devices.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3927" + }, + { + "type": "WEB", + "url": "https://www.digigram.com/download/pyko-out-user-manual-en-jan-2019" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-02T15:15:49Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-qrhc-f2qm-32m6/GHSA-qrhc-f2qm-32m6.json b/advisories/unreviewed/2025/05/GHSA-qrhc-f2qm-32m6/GHSA-qrhc-f2qm-32m6.json new file mode 100644 index 00000000000..f231d0771ca --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-qrhc-f2qm-32m6/GHSA-qrhc-f2qm-32m6.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-qrhc-f2qm-32m6", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-3517" + ], + "details": "Incorrect privilege assignment in PAM JIT elevation feature in Devolutions Server 2025.1.5.0 and earlier allows a PAM user to elevate a previously configured user configured in a PAM JIT account via failure to update the internal account’s SID when updating the username.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-3517" + }, + { + "type": "WEB", + "url": "https://devolutions.net/security/advisories/DEVO-2025-0006" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-266" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T19:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-r3g9-3r7f-gg8r/GHSA-r3g9-3r7f-gg8r.json b/advisories/unreviewed/2025/05/GHSA-r3g9-3r7f-gg8r/GHSA-r3g9-3r7f-gg8r.json new file mode 100644 index 00000000000..6eed4db7d97 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-r3g9-3r7f-gg8r/GHSA-r3g9-3r7f-gg8r.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r3g9-3r7f-gg8r", + "modified": "2025-05-02T15:31:44Z", + "published": "2025-05-02T15:31:44Z", + "aliases": [ + "CVE-2025-32886" + ], + "details": "An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. All packets sent over RF are also sent over UART with USB Shell, allowing someone with local access to gain information about the protocol and intercept sensitive data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32886" + }, + { + "type": "WEB", + "url": "https://github.com/Dollarhyde/goTenna_v1_and_Mesh_vulnerabilities" + }, + { + "type": "WEB", + "url": "https://gotenna.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-923" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-rg65-rpmg-wff5/GHSA-rg65-rpmg-wff5.json b/advisories/unreviewed/2025/05/GHSA-rg65-rpmg-wff5/GHSA-rg65-rpmg-wff5.json index 569243c5f08..d019be28f77 100644 --- a/advisories/unreviewed/2025/05/GHSA-rg65-rpmg-wff5/GHSA-rg65-rpmg-wff5.json +++ b/advisories/unreviewed/2025/05/GHSA-rg65-rpmg-wff5/GHSA-rg65-rpmg-wff5.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-rg65-rpmg-wff5", - "modified": "2025-05-01T18:31:47Z", + "modified": "2025-05-02T15:31:42Z", "published": "2025-05-01T18:31:47Z", "aliases": [ "CVE-2025-44847" ], "details": "TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the setWebWlanIdx function via the webWlanIdx parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-01T17:15:51Z" diff --git a/advisories/unreviewed/2025/05/GHSA-rqv8-f6wr-28h4/GHSA-rqv8-f6wr-28h4.json b/advisories/unreviewed/2025/05/GHSA-rqv8-f6wr-28h4/GHSA-rqv8-f6wr-28h4.json new file mode 100644 index 00000000000..2a8f66a65a4 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-rqv8-f6wr-28h4/GHSA-rqv8-f6wr-28h4.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rqv8-f6wr-28h4", + "modified": "2025-05-02T15:31:48Z", + "published": "2025-05-02T15:31:48Z", + "aliases": [ + "CVE-2025-1883" + ], + "details": "Out-Of-Bounds Write vulnerability exists in the OBJ file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted OBJ file.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-1883" + }, + { + "type": "WEB", + "url": "https://www.3ds.com/vulnerability/advisories" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-02T15:15:48Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-v2xg-gxf7-x426/GHSA-v2xg-gxf7-x426.json b/advisories/unreviewed/2025/05/GHSA-v2xg-gxf7-x426/GHSA-v2xg-gxf7-x426.json new file mode 100644 index 00000000000..0cd8f50c538 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-v2xg-gxf7-x426/GHSA-v2xg-gxf7-x426.json @@ -0,0 +1,44 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-v2xg-gxf7-x426", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-35996" + ], + "details": "KUNBUS PiCtory version 2.11.1 and earlier are vulnerable when an authenticated remote attacker crafts a special filename that can be stored by API endpoints. That filename is later transmitted to the client in order to show a list of configuration files. Due to a missing escape or sanitization, the filename could be executed as HTML script tag resulting in a cross-site-scripting attack.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-35996" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-121-01" + }, + { + "type": "WEB", + "url": "http://packages.revolutionpi.de/pool/main/p/pictory" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-97" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T19:15:58Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vcw3-9m5f-w235/GHSA-vcw3-9m5f-w235.json b/advisories/unreviewed/2025/05/GHSA-vcw3-9m5f-w235/GHSA-vcw3-9m5f-w235.json index e1fb1972015..7e25384c2f5 100644 --- a/advisories/unreviewed/2025/05/GHSA-vcw3-9m5f-w235/GHSA-vcw3-9m5f-w235.json +++ b/advisories/unreviewed/2025/05/GHSA-vcw3-9m5f-w235/GHSA-vcw3-9m5f-w235.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-vcw3-9m5f-w235", - "modified": "2025-05-01T15:31:53Z", + "modified": "2025-05-02T15:31:41Z", "published": "2025-05-01T15:31:53Z", "aliases": [ "CVE-2025-44837" ], "details": "TOTOLINK CPE CP900 V6.3c.1144_B20190715 was discovered to contain a command injection vulnerability in the CloudSrvUserdataVersionCheck function via the url or magicid parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + } + ], "affected": [], "references": [ { @@ -20,8 +25,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-77" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2025-05-01T15:16:20Z" diff --git a/advisories/unreviewed/2025/05/GHSA-vg58-p724-725x/GHSA-vg58-p724-725x.json b/advisories/unreviewed/2025/05/GHSA-vg58-p724-725x/GHSA-vg58-p724-725x.json new file mode 100644 index 00000000000..be8a2a983db --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vg58-p724-725x/GHSA-vg58-p724-725x.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vg58-p724-725x", + "modified": "2025-05-02T15:31:44Z", + "published": "2025-05-02T15:31:44Z", + "aliases": [ + "CVE-2025-32890" + ], + "details": "An issue was discovered on goTenna Mesh devices with app 5.5.3 and firmware 1.1.12. It uses a custom implementation of encryption without any additional integrity checking mechanisms. This leaves messages malleable to an attacker that can access the message.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32890" + }, + { + "type": "WEB", + "url": "https://github.com/Dollarhyde/goTenna_v1_and_Mesh_vulnerabilities" + }, + { + "type": "WEB", + "url": "https://gotenna.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-353" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T18:15:56Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vv7q-66vv-9jp3/GHSA-vv7q-66vv-9jp3.json b/advisories/unreviewed/2025/05/GHSA-vv7q-66vv-9jp3/GHSA-vv7q-66vv-9jp3.json new file mode 100644 index 00000000000..b3a3ab8239f --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vv7q-66vv-9jp3/GHSA-vv7q-66vv-9jp3.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv7q-66vv-9jp3", + "modified": "2025-05-02T15:31:46Z", + "published": "2025-05-02T15:31:46Z", + "aliases": [ + "CVE-2025-46631" + ], + "details": "Improper access controls in the web management portal of the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated remote attacker to enable telnet access to the router's OS by sending a /goform/telnet web request.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46631" + }, + { + "type": "WEB", + "url": "https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46631-enable-telnet-unauthenticated-through-httpd" + }, + { + "type": "WEB", + "url": "https://www.tendacn.com/us/default.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-287" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T20:15:39Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vv8p-v9q5-4pvf/GHSA-vv8p-v9q5-4pvf.json b/advisories/unreviewed/2025/05/GHSA-vv8p-v9q5-4pvf/GHSA-vv8p-v9q5-4pvf.json new file mode 100644 index 00000000000..753dff318d9 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vv8p-v9q5-4pvf/GHSA-vv8p-v9q5-4pvf.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vv8p-v9q5-4pvf", + "modified": "2025-05-02T15:31:44Z", + "published": "2025-05-02T15:31:44Z", + "aliases": [ + "CVE-2025-32887" + ], + "details": "An issue was discovered on goTenna v1 devices with app 5.5.3 and firmware 0.25.5. A command channel includes the next hop. which can be intercepted and used to break frequency hopping.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-32887" + }, + { + "type": "WEB", + "url": "https://github.com/Dollarhyde/goTenna_v1_and_Mesh_vulnerabilities" + }, + { + "type": "WEB", + "url": "https://gotenna.com" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-319" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T18:15:55Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-vx82-68wg-wxq4/GHSA-vx82-68wg-wxq4.json b/advisories/unreviewed/2025/05/GHSA-vx82-68wg-wxq4/GHSA-vx82-68wg-wxq4.json new file mode 100644 index 00000000000..7166ccac4c2 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-vx82-68wg-wxq4/GHSA-vx82-68wg-wxq4.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vx82-68wg-wxq4", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-4174" + ], + "details": "A vulnerability, which was classified as critical, has been found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Username leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-4174" + }, + { + "type": "WEB", + "url": "https://github.com/FLYFISH567/CVE/issues/1" + }, + { + "type": "WEB", + "url": "https://phpgurukul.com" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.306794" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.306794" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.561746" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-74" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T19:15:59Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-w5qh-gchv-44g2/GHSA-w5qh-gchv-44g2.json b/advisories/unreviewed/2025/05/GHSA-w5qh-gchv-44g2/GHSA-w5qh-gchv-44g2.json new file mode 100644 index 00000000000..852c9380733 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-w5qh-gchv-44g2/GHSA-w5qh-gchv-44g2.json @@ -0,0 +1,33 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-w5qh-gchv-44g2", + "modified": "2025-05-02T15:31:45Z", + "published": "2025-05-02T15:31:45Z", + "aliases": [ + "CVE-2025-46627" + ], + "details": "Use of weak credentials in the Tenda RX2 Pro 16.03.30.14 allows an unauthenticated attacker to authenticate to the telnet service by calculating the root password based on easily-obtained device information. The password is based on the last two digits/octets of the MAC address.", + "severity": [], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46627" + }, + { + "type": "WEB", + "url": "https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46627-calculated-os-root-password" + }, + { + "type": "WEB", + "url": "https://www.tendacn.com/us/default.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": null, + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T20:15:38Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/05/GHSA-wf34-hx5v-vq6q/GHSA-wf34-hx5v-vq6q.json b/advisories/unreviewed/2025/05/GHSA-wf34-hx5v-vq6q/GHSA-wf34-hx5v-vq6q.json new file mode 100644 index 00000000000..e8a11ee0b24 --- /dev/null +++ b/advisories/unreviewed/2025/05/GHSA-wf34-hx5v-vq6q/GHSA-wf34-hx5v-vq6q.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wf34-hx5v-vq6q", + "modified": "2025-05-02T15:31:46Z", + "published": "2025-05-02T15:31:46Z", + "aliases": [ + "CVE-2025-46632" + ], + "details": "Initialization vector (IV) reuse in the web management portal of the Tenda RX2 Pro 16.03.30.14 may allow an attacker to discern information about or more easily decrypt encrypted messages between client and server.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-46632" + }, + { + "type": "WEB", + "url": "https://blog.uturn.dev/#/writeups/iot-village/tenda-rx2pro/README?id=cve-2025-46632-static-iv-use-in-httpd" + }, + { + "type": "WEB", + "url": "https://www.tendacn.com/us/default.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-323" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-05-01T20:15:39Z" + } +} \ No newline at end of file