|
921
|
- |
|
-
|
-
|
Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.
New
|
CWE-287
Improper Authentication
|
CVE-2026-49203
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
922
|
- |
|
-
|
-
|
Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.
New
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-49204
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
923
|
- |
|
-
|
-
|
System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-50205
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
924
|
- |
|
-
|
-
|
Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.
New
|
CWE-78
OS Command
|
CVE-2026-50206
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
925
|
- |
|
-
|
-
|
The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellular connectivity.
New
|
CWE-22
Path Traversal
|
CVE-2026-50207
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
926
|
- |
|
-
|
-
|
High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.
New
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2026-50208
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
927
|
- |
|
-
|
-
|
Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.
New
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-50209
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
928
|
- |
|
-
|
-
|
The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption.
New
|
CWE-200
Information Exposure
|
CVE-2026-50210
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
929
|
- |
|
-
|
-
|
Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.
New
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2026-50211
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
930
|
- |
|
-
|
-
|
Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service.
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-50212
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|