A vulnerability was found in D-Link DIR-859 1.06B01. It has been rated as critical. Affected by this issue is some unknown functionality of the file /hedwig.cgi of the component HTTP POST Request Handler. The manipulation of the argument service with the input ../../../../htdocs/webinc/getcfg/DHCPS6.BRIDGE-1.xml leads to path traversal. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is handled as CVE-2024-0769. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to disable the affected component.
Vendor was contacted early and confirmed immediately that the product is end-of-life. It should be retired and replaced.
A vulnerability was found in ABB RMC-100 and RMC-100 LITE. It has been rated as critical. Affected by this issue is some unknown functionality of the component REST Interface. The manipulation leads to stack-based buffer overflow.
This vulnerability is handled as CVE-2025-6072. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as critical has been found in ABB RMC-100 and RMC-100 LITE. This affects an unknown part of the component REST Interface. The manipulation leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2025-6073. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in ABB RMC-100 and RMC-100 LITE. This issue affects some unknown processing of the component MQTT Handler. The manipulation leads to use of hard-coded cryptographic key
.
The identification of this vulnerability is CVE-2025-6071. The attack may be initiated remotely. There is no exploit available.
A vulnerability was found in StarCitizenTools mediawiki-skins-Citizen up to 3.3.x. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to cross site scripting.
This vulnerability is known as CVE-2025-53370. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in IGEL OS. It has been classified as critical. Affected is an unknown function of the component Secure Terminal Services/Secure Shadow Services. The manipulation leads to os command injection. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is traded as CVE-2025-34082. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.