Linksys RE6500 Full disclosure, got 4 CVEs! 🤓
CVE-2020-35713 - Base Score 9.8 Critical
CVE-2020-35714 - Base Score 8.8 High
CVE-2020-35715 - Base Score 8.8 High
CVE-2020-35716 - Base Score 7.5 High
https://t.co/v5lF5e9kgZ
[D-Link DWR-921 | DWR-925 | DWR-118 ] Hardcoded web page brings up telnetd, and hardcoded backdoor credentials allows an attacker to gain root privileges.
Credentials are hidden, coz D-Link won't release any fix.
#dlink#hacking#backdoor
https://t.co/Eew0jaKJwC
@securityaffairs
[CVE-2022-40602] LTE3301-M209 pre-configured password vulnerability.
A similar situation also on D-Link DWR-921, DWR-925, DWR-118.
I'll publish soon a post on my blog. Stay tuned
Thank you @ZyxelNews
https://t.co/86jyYQzvIQ
@ZyXELItalia#backdoor#vulnerability#CVE#networking
D-Link won't fix the vulnerability I have reported.
They claim Lan side only, but it's not.
Waiting for the patch to be released by another (much more professional) manufacturer.
Can't publish the details yet.
#Dlink#vulnerability#0day#rce#router
https://t.co/AEQLx8bOad
@_giovannigrasso@tomasomontanari A banana plant is technically a large herb because it never forms a woody stem the way a tree does. In botanical terms banana plant is not a tree.
However, monkeys attend both.
D-Link, ADB Global rebranded: YAPL Script Language support - version 2.
Never seen/heard before.
Have I to write a decompiler/interpreter on my own?
@valerio do you know something more about?
#ADB#Router#Openwrt#reverse_engineering
@VodafoneIT Ricarica OneClick: for all users who have used their top up service at least once, your email remains stored and exposed forever (even if you change your mobile provider)?
No authentication required.
#vodafone#homobile#privacy