threat-intel XCharge C6 This CISA advisory details a critical vulnerability series affecting XCharge C6 charging controllers worldwide. The vulnerabilities include a firmware validation flaw, a stack-based buffer overflow, and a misconfigured r… CISA Advisories · May 28, 2026 Critical CVE-2026-9037CVE-2026-9038CVE-2026-9039USfirmwarebuffer overflowremote management
threat-intel MacGregor Voyage Data Recorder (VDR) G4e A vulnerability has been identified in MacGregor Voyage Data Recorder (VDR) G4e devices, specifically versions prior to V5.250, due to the use of default credentials, weak password hashing, and hard-coded credentials. Th… CISA Advisories · May 28, 2026 High CVE-2026-42941CVE-2026-42951CVE-2026-44611DKdefault credentialsvdrfirmware
vulnerability CP Plus 8 Ch. Network Video Recorder A cross-site scripting (XSS) vulnerability has been identified in CP Plus 8 Ch. Network Video Recorder devices (CP-UNR-108F1 Hardware V1.0, CP-UNR-108F1 Web V3.2.7.128806, and CP-UNR-108F1 System V4.001.00AT009.0.R). Att… CISA Advisories · May 28, 2026 High CVE-2026-6824INNPAExsscwe-79firmware
vulnerability ABB Terra AC This report details a vulnerability in ABB Terra AC wallbox chargers, specifically versions up to 1.8.34. An attacker could exploit unencrypted communication to the Charging Station Management System (CSMS) by sending sp… CISA Advisories · May 26, 2026 Critical CVE-2025-5517WOocppheap overflowfirmware
threat-intel ABB AC500 V2 ABB has identified and addressed vulnerabilities in its AC500 V2 PLC firmware, specifically versions up to 2.5.3. An attacker could potentially access Modbus telegram fragments by sending unsupported function codes to th… CISA Advisories · May 26, 2026 Medium CVE-2025-7745WOmodbusplcfirmware
vulnerability ABB B&R PCs This CISA advisory details a vulnerability (CVE-2023-45229 through CVE-2023-45237) affecting ABB B&R PCs, specifically versions of the EDK2 Network Package. The vulnerability, a critical out-of-bounds read, allows for re… CISA Advisories · May 21, 2026 Critical CVE-2023-45229CVE-2023-45230CVE-2023-45231uefidhcpv6remote code execution
vulnerability ABB Terra AC Wallbox ABB has identified and addressed vulnerabilities in its Terra AC Wallbox product versions (<=1.8.33). These vulnerabilities, specifically related to heap and stack memory pollution due to improper handling of communicati… CISA Advisories · May 21, 2026 Medium CVE-2025-10504CVE-2025-12142CVE-2025-12143GLbluetoothfirmwarebuffer overflow
vulnerability Kieback & Peter DDC Building Controllers This CISA advisory details a cross-site scripting (XSS) vulnerability affecting several versions of Kieback & Peter’s DDC Building Controllers. The vulnerability, CVE-2026-4293, allows an attacker to execute JavaScript c… CISA Advisories · May 19, 2026 Medium CVE-2026-4293AUATCNxssbuilding automationot
vulnerability ZKTeco CCTV Cameras A vulnerability has been identified in ZKTeco CCTV cameras, specifically models utilizing the SSC335-GC2063-Face-0b77 Solution firmware, allowing unauthorized access to camera credentials and configuration information. T… CISA Advisories · May 19, 2026 Medium CVE-2026-8598CHcctvcameraauthentication
threat-intel Bypassing On-Camera Age-Verification Checks This article discusses a research paper detailing a new approach to zero-knowledge proofs that achieves perfect soundness, no interaction, and no setup, effectively addressing key limitations of existing zero-knowledge p… Schneier on Security · May 15, 2026 Medium zero-knowledgefirmwarehardware