Endpunktsicherheit
🔴 CVE-2025-71318: Critical Schwachstelle
NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request...
🔴 CVE-2025-71317: Critical Schwachstelle
NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative access. A remote, unauthenticated...
🔴 CVE-2026-45744: Critical Schwachstelle
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the...
ENDPUNKTSICHERHEIT
Fake Sites Mimicking Open-Source Tools Rank High on Google to Deliver Malware via TDS
Cybersecurity researchers have flagged a large-scale operation that impersonates open-source and freeware projects to funnel unsuspecting users through a Traffic...
ENDPUNKTSICHERHEIT
Android Spyware Asin Targets Arabic Users via Fake News, PDF and War Map Apps
Arabic-speaking users have emerged as the target of a new Android spyware codenamed Asin, according to findings from ESET. The...
🟠 CVE-2026-50213: High Luecke in Acer Connect_M6E_5G_Firmware
The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings.
🟠 CVE-2026-50209: High Luecke in Acer Connect_M6E_5G_Firmware
Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to...
🟠 CVE-2019-25732: High Schwachstelle
PHP EI-Tube Script 3 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting...
🟠 CVE-2019-25728: High Schwachstelle
Care2x 2.7 contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL commands by manipulating the ck_config...
🟠 CVE-2026-49203: High Luecke in Acer Connect_M6E_5G_Firmware
Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or...