Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Coconut

#15982of 55,138
17.5Total CVSS
Vulnerabilities · 2
High
1
Critical
1
PT-2026-67572
10
2026-08-04
Gl.Inet · Gl-Mt3000 · CVE-2026-18686
A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add user of the file /cgi-bin/glc of the component nas-web RPC Wrapper. Performing a manipulation results in command injection. The attack can be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure and confirmed the existence of the vulnerability.
PT-2026-57524
7.5
2026-07-12
H3C · Nx15 · CVE-2026-15479
**Name of the Vulnerable Software and Affected Versions** H3C NX15 version V100R017 **Description** A flaw exists in the Administrator Password Modification Endpoint within the `change passwd()` function of the '/api/login/modify' endpoint. Remote manipulation of the `newPass` argument can lead to weak password recovery. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the '/api/login/modify' endpoint to minimize the risk of exploitation.