Common Vulnerabilities and Exposures (CVE)

CVE-2026-86151

Sep 5, 2026 23:45:09 UTC

A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os command injection. T...

CVE-2026-86150

Sep 5, 2026 23:00:12 UTC

A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be la...

CVE-2026-86149

Sep 5, 2026 22:00:09 UTC

A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initi...

CVE-2026-86148

Sep 5, 2026 21:45:09 UTC

A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection...

CVE-2026-7163

Sep 5, 2026 21:11:43 UTC

A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-scoped privileges to obtain administrative c...

CVE-2026-86060

Sep 5, 2026 20:41:30 UTC

RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation require...

CVE-2026-67281

Sep 5, 2026 20:40:58 UTC

RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare th...

CVE-2026-67279

Sep 5, 2026 20:40:29 UTC

RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the se...

CVE-2026-67278

Sep 5, 2026 20:40:10 UTC

MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures during X.509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public ce...

CVE-2026-67277

Sep 5, 2026 20:39:44 UTC

RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an u...

CVE-2026-67276

Sep 5, 2026 20:39:06 UTC

RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplie...

CVE-2026-86207

Sep 5, 2026 19:20:37 UTC

An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs

CVE-2026-86206

Sep 5, 2026 19:19:47 UTC

A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4

CVE-2026-18238

Sep 5, 2026 18:51:57 UTC

The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process me...

CVE-2026-18313

Sep 5, 2026 18:51:32 UTC

rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious client can cause the...