|
1261
|
- |
|
-
|
-
|
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
|
CWE-200
Information Exposure
|
CVE-2026-49187
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1262
|
- |
|
-
|
-
|
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
|
CWE-489
Exposure of Data Element to Wrong Session
|
CVE-2026-49188
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1263
|
- |
|
-
|
-
|
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.
|
CWE-269
Improper Privilege Management
|
CVE-2026-49189
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1264
|
- |
|
-
|
-
|
The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.
|
CWE-78
OS Command
|
CVE-2026-49190
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1265
|
- |
|
-
|
-
|
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.
|
CWE-287
Improper Authentication
|
CVE-2026-49191
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1266
|
- |
|
-
|
-
|
The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-49192
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1267
|
- |
|
-
|
-
|
Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.
|
CWE-200
Information Exposure
|
CVE-2026-49193
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1268
|
- |
|
-
|
-
|
The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.
|
CWE-287
Improper Authentication
|
CVE-2026-49194
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1269
|
- |
|
-
|
-
|
Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft.
|
CWE-287
Improper Authentication
|
CVE-2026-49202
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1270
|
- |
|
-
|
-
|
Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.
|
CWE-287
Improper Authentication
|
CVE-2026-49203
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|