diff --git a/advisories/unreviewed/2025/06/GHSA-55hh-327m-68hj/GHSA-55hh-327m-68hj.json b/advisories/unreviewed/2025/06/GHSA-55hh-327m-68hj/GHSA-55hh-327m-68hj.json new file mode 100644 index 00000000000..153620405a8 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-55hh-327m-68hj/GHSA-55hh-327m-68hj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55hh-327m-68hj", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-0036" + ], + "details": "In AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic operations could cause data to be incorrectly written to and read from invalid locations as well as returning incorrect cryptographic data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0036" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-8011.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T00:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-65vc-89h4-wvx6/GHSA-65vc-89h4-wvx6.json b/advisories/unreviewed/2025/06/GHSA-65vc-89h4-wvx6/GHSA-65vc-89h4-wvx6.json new file mode 100644 index 00000000000..62d2c0f59c2 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-65vc-89h4-wvx6/GHSA-65vc-89h4-wvx6.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65vc-89h4-wvx6", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-5899" + ], + "details": "A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to free of memory not on the heap. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5899" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1YPJLiBzOwVTcc2FzdawYxBJWGujwqy7o/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://savannah.gnu.org/bugs/index.php?67072" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311671" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311671" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.586106" + }, + { + "type": "WEB", + "url": "https://www.gnu.org" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-590" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6mq6-6457-rccm/GHSA-6mq6-6457-rccm.json b/advisories/unreviewed/2025/06/GHSA-6mq6-6457-rccm/GHSA-6mq6-6457-rccm.json new file mode 100644 index 00000000000..a7db5740ff1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6mq6-6457-rccm/GHSA-6mq6-6457-rccm.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mq6-6457-rccm", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-5902" + ], + "details": "A vulnerability was found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This issue affects the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument slaveIpList leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5902" + }, + { + "type": "WEB", + "url": "https://candle-throne-f75.notion.site/TOTOLINK-T10-setUpgradeFW-20bdf0aa11858089bc28f634bb140d00" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311675" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311675" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592246" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T23:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-82vq-mq3h-xx6f/GHSA-82vq-mq3h-xx6f.json b/advisories/unreviewed/2025/06/GHSA-82vq-mq3h-xx6f/GHSA-82vq-mq3h-xx6f.json new file mode 100644 index 00000000000..e72c5e73352 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-82vq-mq3h-xx6f/GHSA-82vq-mq3h-xx6f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82vq-mq3h-xx6f", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-26468" + ], + "details": "CyberData \n011209 \n\n\nIntercom exposes features that could allow an unauthenticated to gain \naccess and cause a denial-of-service condition or system disruption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26468" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-155-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T23:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8cxq-rp45-79vm/GHSA-8cxq-rp45-79vm.json b/advisories/unreviewed/2025/06/GHSA-8cxq-rp45-79vm/GHSA-8cxq-rp45-79vm.json new file mode 100644 index 00000000000..7acea9166f7 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8cxq-rp45-79vm/GHSA-8cxq-rp45-79vm.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cxq-rp45-79vm", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-5900" + ], + "details": "A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5900" + }, + { + "type": "WEB", + "url": "https://candle-throne-f75.notion.site/Tenda-AC9-fromSysToolReboot-20adf0aa1185806a9d20ee5c355c08a6?pvs=73" + }, + { + "type": "WEB", + "url": "https://candle-throne-f75.notion.site/Tenda-AC9-fromSysToolRestoreSet-20adf0aa11858094a25ae21f9b4203da" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311673" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311673" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592198" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592199" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8vpj-4j9f-97qc/GHSA-8vpj-4j9f-97qc.json b/advisories/unreviewed/2025/06/GHSA-8vpj-4j9f-97qc/GHSA-8vpj-4j9f-97qc.json new file mode 100644 index 00000000000..08b65b961f0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8vpj-4j9f-97qc/GHSA-8vpj-4j9f-97qc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vpj-4j9f-97qc", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-0037" + ], + "details": "In AMD Versal Adaptive SoC devices, the lack of address validation when executing PLM runtime services through the PLM firmware can allow access to isolated or protected memory spaces, resulting in the loss of integrity and confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0037" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-8010.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T00:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-98mq-29fh-72m6/GHSA-98mq-29fh-72m6.json b/advisories/unreviewed/2025/06/GHSA-98mq-29fh-72m6/GHSA-98mq-29fh-72m6.json new file mode 100644 index 00000000000..c45929c5cbe --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-98mq-29fh-72m6/GHSA-98mq-29fh-72m6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98mq-29fh-72m6", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-30507" + ], + "details": "CyberData 011209 Intercom could allow an unauthenticated user to gather sensitive information through blind SQL injections.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30507" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-155-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T23:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-g6rr-5fcq-xjcm/GHSA-g6rr-5fcq-xjcm.json b/advisories/unreviewed/2025/06/GHSA-g6rr-5fcq-xjcm/GHSA-g6rr-5fcq-xjcm.json new file mode 100644 index 00000000000..0f71de6567d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-g6rr-5fcq-xjcm/GHSA-g6rr-5fcq-xjcm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6rr-5fcq-xjcm", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-30184" + ], + "details": "CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30184" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-155-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hjfc-fv59-fjj6/GHSA-hjfc-fv59-fjj6.json b/advisories/unreviewed/2025/06/GHSA-hjfc-fv59-fjj6/GHSA-hjfc-fv59-fjj6.json new file mode 100644 index 00000000000..a36f11cc6fb --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hjfc-fv59-fjj6/GHSA-hjfc-fv59-fjj6.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjfc-fv59-fjj6", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-5898" + ], + "details": "A vulnerability classified as critical has been found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to out-of-bounds write. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5898" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1ZigqDFZQn5YUWFLu1V2juDGWQgbJFAtX/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://savannah.gnu.org/bugs/index.php?67071" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311670" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311670" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.586105" + }, + { + "type": "WEB", + "url": "https://www.gnu.org" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-j6x4-9c7c-pm84/GHSA-j6x4-9c7c-pm84.json b/advisories/unreviewed/2025/06/GHSA-j6x4-9c7c-pm84/GHSA-j6x4-9c7c-pm84.json new file mode 100644 index 00000000000..a02a8a5941b --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-j6x4-9c7c-pm84/GHSA-j6x4-9c7c-pm84.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6x4-9c7c-pm84", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-30183" + ], + "details": "CyberData 011209 Intercom\n does not properly store or protect web server admin credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30183" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-155-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T23:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jfcx-jqxf-6323/GHSA-jfcx-jqxf-6323.json b/advisories/unreviewed/2025/06/GHSA-jfcx-jqxf-6323/GHSA-jfcx-jqxf-6323.json new file mode 100644 index 00000000000..ddcfad690a1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jfcx-jqxf-6323/GHSA-jfcx-jqxf-6323.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfcx-jqxf-6323", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-5901" + ], + "details": "A vulnerability has been found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument File leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5901" + }, + { + "type": "WEB", + "url": "https://candle-throne-f75.notion.site/TOTOLINK-T10-UploadCustomModule-20bdf0aa118580d59961cd545582c118" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311674" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311674" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592243" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T23:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-m3fg-4m85-w9f7/GHSA-m3fg-4m85-w9f7.json b/advisories/unreviewed/2025/06/GHSA-m3fg-4m85-w9f7/GHSA-m3fg-4m85-w9f7.json new file mode 100644 index 00000000000..8e012b885da --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-m3fg-4m85-w9f7/GHSA-m3fg-4m85-w9f7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3fg-4m85-w9f7", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-30515" + ], + "details": "CyberData 011209 Intercom\n \ncould allow an authenticated attacker to upload arbitrary files to multiple locations within the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30515" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-155-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T23:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-m742-x7cw-3g4q/GHSA-m742-x7cw-3g4q.json b/advisories/unreviewed/2025/06/GHSA-m742-x7cw-3g4q/GHSA-m742-x7cw-3g4q.json new file mode 100644 index 00000000000..20d20d475f1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-m742-x7cw-3g4q/GHSA-m742-x7cw-3g4q.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m742-x7cw-3g4q", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-5904" + ], + "details": "A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability is the function setWiFiMeshName of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument device_name leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5904" + }, + { + "type": "WEB", + "url": "https://candle-throne-f75.notion.site/TOTOLINK-T10-setWiFiMeshName-20bdf0aa1185806eb922dbd496c4a4b4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311677" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311677" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592264" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T00:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-pwwc-x5p3-pqjj/GHSA-pwwc-x5p3-pqjj.json b/advisories/unreviewed/2025/06/GHSA-pwwc-x5p3-pqjj/GHSA-pwwc-x5p3-pqjj.json new file mode 100644 index 00000000000..9c2aac00905 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-pwwc-x5p3-pqjj/GHSA-pwwc-x5p3-pqjj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwwc-x5p3-pqjj", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-5903" + ], + "details": "A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been classified as critical. Affected is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument desc leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5903" + }, + { + "type": "WEB", + "url": "https://candle-throne-f75.notion.site/TOTOLINK-T10-setWiFiAclRules-20bdf0aa118580399a8df6ba2a44c197" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311676" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311676" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592247" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T00:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-r36p-hj2v-vj2h/GHSA-r36p-hj2v-vj2h.json b/advisories/unreviewed/2025/06/GHSA-r36p-hj2v-vj2h/GHSA-r36p-hj2v-vj2h.json new file mode 100644 index 00000000000..6106f6e3375 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-r36p-hj2v-vj2h/GHSA-r36p-hj2v-vj2h.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r36p-hj2v-vj2h", + "modified": "2025-06-10T00:30:31Z", + "published": "2025-06-10T00:30:31Z", + "aliases": [ + "CVE-2025-5905" + ], + "details": "A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been rated as critical. Affected by this issue is the function setWiFiRepeaterCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument Password leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5905" + }, + { + "type": "WEB", + "url": "https://candle-throne-f75.notion.site/TOTOLINK-T10-setWiFiRepeaterCfg-20bdf0aa118580bd8cd0da62d4d2e47f?pvs=73" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311678" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311678" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592265" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T00:15:22Z" + } +} \ No newline at end of file