|
911
|
- |
|
-
|
-
|
The local MQTT broker does not enforce topic-level Access Control Lists (ACLs). This allows any client to subscribe using wildcard characters (# or +) to enumerate hidden network devices or publish r…
New
|
CWE-287
Improper Authentication
|
CVE-2026-49186
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
912
|
- |
|
-
|
-
|
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
New
|
CWE-200
Information Exposure
|
CVE-2026-49187
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
913
|
- |
|
-
|
-
|
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
New
|
CWE-489
Exposure of Data Element to Wrong Session
|
CVE-2026-49188
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
914
|
- |
|
-
|
-
|
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-49189
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
915
|
- |
|
-
|
-
|
The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.
New
|
CWE-78
OS Command
|
CVE-2026-49190
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
916
|
- |
|
-
|
-
|
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.
New
|
CWE-287
Improper Authentication
|
CVE-2026-49191
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
917
|
- |
|
-
|
-
|
The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-49192
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
918
|
- |
|
-
|
-
|
Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.
New
|
CWE-200
Information Exposure
|
CVE-2026-49193
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
919
|
- |
|
-
|
-
|
The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.
New
|
CWE-287
Improper Authentication
|
CVE-2026-49194
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
920
|
- |
|
-
|
-
|
Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft.
New
|
CWE-287
Improper Authentication
|
CVE-2026-49202
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|