do4choo

3 exploits Active since Mar 2026
CVE-2026-3227 NOMISEC MEDIUM WORKING POC
Authenticated Command Injection on TP-Link TL-WR802N, TL-WR841N and TL-WR840N
A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import function allows an authenticated attacker to upload a crafted configuration file that results in execution of OS commands with root privileges during port-trigger processing. Successful exploitation allows an authenticated attacker to execute system commands with root privileges, leading to full device compromise.
41 stars
CVSS 6.8
CVE-2026-53694 GITHUB HIGH python WORKING POC
Potential local privileges escalation through argument injection in the nxchmod.sh script
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Nomachine allows Argument Injection.This issue affects Nomachine: before 9.5.7, before 8.23.2.
CVE-2026-3227 GITHUB MEDIUM python WORKING POC
Authenticated Command Injection on TP-Link TL-WR802N, TL-WR841N and TL-WR840N
A command injection vulnerability was identified in TP-Link TL-WR802N v4, TL-WR841N v14, and TL-WR840N v6 due to improper neutralization of special elements used in an OS command. In the router configuration import function allows an authenticated attacker to upload a crafted configuration file that results in execution of OS commands with root privileges during port-trigger processing. Successful exploitation allows an authenticated attacker to execute system commands with root privileges, leading to full device compromise.
CVSS 6.8