From 98d3202bae0f1aa1ba3359b3d883fbb650430abe Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 10 Jun 2025 00:32:35 +0000 Subject: [PATCH] Publish Advisories GHSA-55hh-327m-68hj GHSA-65vc-89h4-wvx6 GHSA-6mq6-6457-rccm GHSA-82vq-mq3h-xx6f GHSA-8cxq-rp45-79vm GHSA-8vpj-4j9f-97qc GHSA-98mq-29fh-72m6 GHSA-g6rr-5fcq-xjcm GHSA-hjfc-fv59-fjj6 GHSA-j6x4-9c7c-pm84 GHSA-jfcx-jqxf-6323 GHSA-m3fg-4m85-w9f7 GHSA-m742-x7cw-3g4q GHSA-pwwc-x5p3-pqjj GHSA-r36p-hj2v-vj2h --- .../GHSA-55hh-327m-68hj.json | 36 +++++++++++ .../GHSA-65vc-89h4-wvx6.json | 60 +++++++++++++++++ .../GHSA-6mq6-6457-rccm.json | 56 ++++++++++++++++ .../GHSA-82vq-mq3h-xx6f.json | 40 ++++++++++++ .../GHSA-8cxq-rp45-79vm.json | 64 +++++++++++++++++++ .../GHSA-8vpj-4j9f-97qc.json | 36 +++++++++++ .../GHSA-98mq-29fh-72m6.json | 40 ++++++++++++ .../GHSA-g6rr-5fcq-xjcm.json | 40 ++++++++++++ .../GHSA-hjfc-fv59-fjj6.json | 60 +++++++++++++++++ .../GHSA-j6x4-9c7c-pm84.json | 40 ++++++++++++ .../GHSA-jfcx-jqxf-6323.json | 56 ++++++++++++++++ .../GHSA-m3fg-4m85-w9f7.json | 40 ++++++++++++ .../GHSA-m742-x7cw-3g4q.json | 56 ++++++++++++++++ .../GHSA-pwwc-x5p3-pqjj.json | 56 ++++++++++++++++ .../GHSA-r36p-hj2v-vj2h.json | 56 ++++++++++++++++ 15 files changed, 736 insertions(+) create mode 100644 advisories/unreviewed/2025/06/GHSA-55hh-327m-68hj/GHSA-55hh-327m-68hj.json create mode 100644 advisories/unreviewed/2025/06/GHSA-65vc-89h4-wvx6/GHSA-65vc-89h4-wvx6.json create mode 100644 advisories/unreviewed/2025/06/GHSA-6mq6-6457-rccm/GHSA-6mq6-6457-rccm.json create mode 100644 advisories/unreviewed/2025/06/GHSA-82vq-mq3h-xx6f/GHSA-82vq-mq3h-xx6f.json create mode 100644 advisories/unreviewed/2025/06/GHSA-8cxq-rp45-79vm/GHSA-8cxq-rp45-79vm.json create mode 100644 advisories/unreviewed/2025/06/GHSA-8vpj-4j9f-97qc/GHSA-8vpj-4j9f-97qc.json create mode 100644 advisories/unreviewed/2025/06/GHSA-98mq-29fh-72m6/GHSA-98mq-29fh-72m6.json create mode 100644 advisories/unreviewed/2025/06/GHSA-g6rr-5fcq-xjcm/GHSA-g6rr-5fcq-xjcm.json create mode 100644 advisories/unreviewed/2025/06/GHSA-hjfc-fv59-fjj6/GHSA-hjfc-fv59-fjj6.json create mode 100644 advisories/unreviewed/2025/06/GHSA-j6x4-9c7c-pm84/GHSA-j6x4-9c7c-pm84.json create mode 100644 advisories/unreviewed/2025/06/GHSA-jfcx-jqxf-6323/GHSA-jfcx-jqxf-6323.json create mode 100644 advisories/unreviewed/2025/06/GHSA-m3fg-4m85-w9f7/GHSA-m3fg-4m85-w9f7.json create mode 100644 advisories/unreviewed/2025/06/GHSA-m742-x7cw-3g4q/GHSA-m742-x7cw-3g4q.json create mode 100644 advisories/unreviewed/2025/06/GHSA-pwwc-x5p3-pqjj/GHSA-pwwc-x5p3-pqjj.json create mode 100644 advisories/unreviewed/2025/06/GHSA-r36p-hj2v-vj2h/GHSA-r36p-hj2v-vj2h.json diff --git a/advisories/unreviewed/2025/06/GHSA-55hh-327m-68hj/GHSA-55hh-327m-68hj.json b/advisories/unreviewed/2025/06/GHSA-55hh-327m-68hj/GHSA-55hh-327m-68hj.json new file mode 100644 index 00000000000..153620405a8 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-55hh-327m-68hj/GHSA-55hh-327m-68hj.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-55hh-327m-68hj", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-0036" + ], + "details": "In AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic operations could cause data to be incorrectly written to and read from invalid locations as well as returning incorrect cryptographic data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0036" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-8011.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-497" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T00:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-65vc-89h4-wvx6/GHSA-65vc-89h4-wvx6.json b/advisories/unreviewed/2025/06/GHSA-65vc-89h4-wvx6/GHSA-65vc-89h4-wvx6.json new file mode 100644 index 00000000000..62d2c0f59c2 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-65vc-89h4-wvx6/GHSA-65vc-89h4-wvx6.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-65vc-89h4-wvx6", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-5899" + ], + "details": "A vulnerability classified as critical was found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected by this vulnerability is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to free of memory not on the heap. An attack has to be approached locally. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5899" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1YPJLiBzOwVTcc2FzdawYxBJWGujwqy7o/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://savannah.gnu.org/bugs/index.php?67072" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311671" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311671" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.586106" + }, + { + "type": "WEB", + "url": "https://www.gnu.org" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-590" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-6mq6-6457-rccm/GHSA-6mq6-6457-rccm.json b/advisories/unreviewed/2025/06/GHSA-6mq6-6457-rccm/GHSA-6mq6-6457-rccm.json new file mode 100644 index 00000000000..a7db5740ff1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-6mq6-6457-rccm/GHSA-6mq6-6457-rccm.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-6mq6-6457-rccm", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-5902" + ], + "details": "A vulnerability was found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This issue affects the function setUpgradeFW of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument slaveIpList leads to buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5902" + }, + { + "type": "WEB", + "url": "https://candle-throne-f75.notion.site/TOTOLINK-T10-setUpgradeFW-20bdf0aa11858089bc28f634bb140d00" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311675" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311675" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592246" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T23:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-82vq-mq3h-xx6f/GHSA-82vq-mq3h-xx6f.json b/advisories/unreviewed/2025/06/GHSA-82vq-mq3h-xx6f/GHSA-82vq-mq3h-xx6f.json new file mode 100644 index 00000000000..e72c5e73352 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-82vq-mq3h-xx6f/GHSA-82vq-mq3h-xx6f.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-82vq-mq3h-xx6f", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-26468" + ], + "details": "CyberData \n011209 \n\n\nIntercom exposes features that could allow an unauthenticated to gain \naccess and cause a denial-of-service condition or system disruption.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-26468" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-155-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-306" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T23:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8cxq-rp45-79vm/GHSA-8cxq-rp45-79vm.json b/advisories/unreviewed/2025/06/GHSA-8cxq-rp45-79vm/GHSA-8cxq-rp45-79vm.json new file mode 100644 index 00000000000..7acea9166f7 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8cxq-rp45-79vm/GHSA-8cxq-rp45-79vm.json @@ -0,0 +1,64 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8cxq-rp45-79vm", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-5900" + ], + "details": "A vulnerability, which was classified as problematic, was found in Tenda AC9 15.03.02.13. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5900" + }, + { + "type": "WEB", + "url": "https://candle-throne-f75.notion.site/Tenda-AC9-fromSysToolReboot-20adf0aa1185806a9d20ee5c355c08a6?pvs=73" + }, + { + "type": "WEB", + "url": "https://candle-throne-f75.notion.site/Tenda-AC9-fromSysToolRestoreSet-20adf0aa11858094a25ae21f9b4203da" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311673" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311673" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592198" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592199" + }, + { + "type": "WEB", + "url": "https://www.tenda.com.cn" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-352" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-8vpj-4j9f-97qc/GHSA-8vpj-4j9f-97qc.json b/advisories/unreviewed/2025/06/GHSA-8vpj-4j9f-97qc/GHSA-8vpj-4j9f-97qc.json new file mode 100644 index 00000000000..08b65b961f0 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-8vpj-4j9f-97qc/GHSA-8vpj-4j9f-97qc.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-8vpj-4j9f-97qc", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-0037" + ], + "details": "In AMD Versal Adaptive SoC devices, the lack of address validation when executing PLM runtime services through the PLM firmware can allow access to isolated or protected memory spaces, resulting in the loss of integrity and confidentiality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-0037" + }, + { + "type": "WEB", + "url": "https://www.amd.com/en/resources/product-security/bulletin/amd-sb-8010.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-20" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T00:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-98mq-29fh-72m6/GHSA-98mq-29fh-72m6.json b/advisories/unreviewed/2025/06/GHSA-98mq-29fh-72m6/GHSA-98mq-29fh-72m6.json new file mode 100644 index 00000000000..c45929c5cbe --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-98mq-29fh-72m6/GHSA-98mq-29fh-72m6.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-98mq-29fh-72m6", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-30507" + ], + "details": "CyberData 011209 Intercom could allow an unauthenticated user to gather sensitive information through blind SQL injections.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30507" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-155-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-89" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T23:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-g6rr-5fcq-xjcm/GHSA-g6rr-5fcq-xjcm.json b/advisories/unreviewed/2025/06/GHSA-g6rr-5fcq-xjcm/GHSA-g6rr-5fcq-xjcm.json new file mode 100644 index 00000000000..0f71de6567d --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-g6rr-5fcq-xjcm/GHSA-g6rr-5fcq-xjcm.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g6rr-5fcq-xjcm", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-30184" + ], + "details": "CyberData 011209 Intercom could allow an unauthenticated user access to the Web Interface through an alternate path.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30184" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-155-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-288" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T22:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-hjfc-fv59-fjj6/GHSA-hjfc-fv59-fjj6.json b/advisories/unreviewed/2025/06/GHSA-hjfc-fv59-fjj6/GHSA-hjfc-fv59-fjj6.json new file mode 100644 index 00000000000..a36f11cc6fb --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-hjfc-fv59-fjj6/GHSA-hjfc-fv59-fjj6.json @@ -0,0 +1,60 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hjfc-fv59-fjj6", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-5898" + ], + "details": "A vulnerability classified as critical has been found in GNU PSPP 82fb509fb2fedd33e7ac0c46ca99e108bb3bdffb. Affected is the function parse_variables_option of the file utilities/pspp-convert.c. The manipulation leads to out-of-bounds write. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5898" + }, + { + "type": "WEB", + "url": "https://drive.google.com/file/d/1ZigqDFZQn5YUWFLu1V2juDGWQgbJFAtX/view?usp=sharing" + }, + { + "type": "WEB", + "url": "https://savannah.gnu.org/bugs/index.php?67071" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311670" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311670" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.586105" + }, + { + "type": "WEB", + "url": "https://www.gnu.org" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T22:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-j6x4-9c7c-pm84/GHSA-j6x4-9c7c-pm84.json b/advisories/unreviewed/2025/06/GHSA-j6x4-9c7c-pm84/GHSA-j6x4-9c7c-pm84.json new file mode 100644 index 00000000000..a02a8a5941b --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-j6x4-9c7c-pm84/GHSA-j6x4-9c7c-pm84.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-j6x4-9c7c-pm84", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-30183" + ], + "details": "CyberData 011209 Intercom\n does not properly store or protect web server admin credentials.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30183" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-155-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-522" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T23:15:21Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-jfcx-jqxf-6323/GHSA-jfcx-jqxf-6323.json b/advisories/unreviewed/2025/06/GHSA-jfcx-jqxf-6323/GHSA-jfcx-jqxf-6323.json new file mode 100644 index 00000000000..ddcfad690a1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-jfcx-jqxf-6323/GHSA-jfcx-jqxf-6323.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jfcx-jqxf-6323", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-5901" + ], + "details": "A vulnerability has been found in TOTOLINK T10 4.1.8cu.5207 and classified as critical. This vulnerability affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument File leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5901" + }, + { + "type": "WEB", + "url": "https://candle-throne-f75.notion.site/TOTOLINK-T10-UploadCustomModule-20bdf0aa118580d59961cd545582c118" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311674" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311674" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592243" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T23:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-m3fg-4m85-w9f7/GHSA-m3fg-4m85-w9f7.json b/advisories/unreviewed/2025/06/GHSA-m3fg-4m85-w9f7/GHSA-m3fg-4m85-w9f7.json new file mode 100644 index 00000000000..8e012b885da --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-m3fg-4m85-w9f7/GHSA-m3fg-4m85-w9f7.json @@ -0,0 +1,40 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m3fg-4m85-w9f7", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-30515" + ], + "details": "CyberData 011209 Intercom\n \ncould allow an authenticated attacker to upload arbitrary files to multiple locations within the system.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-30515" + }, + { + "type": "WEB", + "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-155-01" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-35" + ], + "severity": "CRITICAL", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-09T23:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-m742-x7cw-3g4q/GHSA-m742-x7cw-3g4q.json b/advisories/unreviewed/2025/06/GHSA-m742-x7cw-3g4q/GHSA-m742-x7cw-3g4q.json new file mode 100644 index 00000000000..20d20d475f1 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-m742-x7cw-3g4q/GHSA-m742-x7cw-3g4q.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-m742-x7cw-3g4q", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-5904" + ], + "details": "A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been declared as critical. Affected by this vulnerability is the function setWiFiMeshName of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument device_name leads to buffer overflow. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5904" + }, + { + "type": "WEB", + "url": "https://candle-throne-f75.notion.site/TOTOLINK-T10-setWiFiMeshName-20bdf0aa1185806eb922dbd496c4a4b4" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311677" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311677" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592264" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T00:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-pwwc-x5p3-pqjj/GHSA-pwwc-x5p3-pqjj.json b/advisories/unreviewed/2025/06/GHSA-pwwc-x5p3-pqjj/GHSA-pwwc-x5p3-pqjj.json new file mode 100644 index 00000000000..9c2aac00905 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-pwwc-x5p3-pqjj/GHSA-pwwc-x5p3-pqjj.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-pwwc-x5p3-pqjj", + "modified": "2025-06-10T00:30:30Z", + "published": "2025-06-10T00:30:30Z", + "aliases": [ + "CVE-2025-5903" + ], + "details": "A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been classified as critical. Affected is the function setWiFiAclRules of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument desc leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5903" + }, + { + "type": "WEB", + "url": "https://candle-throne-f75.notion.site/TOTOLINK-T10-setWiFiAclRules-20bdf0aa118580399a8df6ba2a44c197" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311676" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311676" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592247" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T00:15:22Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/06/GHSA-r36p-hj2v-vj2h/GHSA-r36p-hj2v-vj2h.json b/advisories/unreviewed/2025/06/GHSA-r36p-hj2v-vj2h/GHSA-r36p-hj2v-vj2h.json new file mode 100644 index 00000000000..6106f6e3375 --- /dev/null +++ b/advisories/unreviewed/2025/06/GHSA-r36p-hj2v-vj2h/GHSA-r36p-hj2v-vj2h.json @@ -0,0 +1,56 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r36p-hj2v-vj2h", + "modified": "2025-06-10T00:30:31Z", + "published": "2025-06-10T00:30:31Z", + "aliases": [ + "CVE-2025-5905" + ], + "details": "A vulnerability was found in TOTOLINK T10 4.1.8cu.5207. It has been rated as critical. Affected by this issue is the function setWiFiRepeaterCfg of the file /cgi-bin/cstecgi.cgi of the component POST Request Handler. The manipulation of the argument Password leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + }, + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-5905" + }, + { + "type": "WEB", + "url": "https://candle-throne-f75.notion.site/TOTOLINK-T10-setWiFiRepeaterCfg-20bdf0aa118580bd8cd0da62d4d2e47f?pvs=73" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?ctiid.311678" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?id.311678" + }, + { + "type": "WEB", + "url": "https://vuldb.com/?submit.592265" + }, + { + "type": "WEB", + "url": "https://www.totolink.net" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-119" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-06-10T00:15:22Z" + } +} \ No newline at end of file