meigui637

2 exploits Active since Sep 2025
CVE-2025-55847 WRITEUP HIGH WRITEUP
Wavlink M86X3A_V240730 - Buffer Overflow
Wavlink M86X3A_V240730 contains a buffer overflow vulnerability in the /cgi-bin/ExportAllSettings.cgi file. The vulnerability arises because the Cookie parameter does not properly validate the length of input data. Attackers can exploit this to execute arbitrary code or cause a denial of service (DoS) on the system
CVSS 8.8
CVE-2025-55848 WRITEUP HIGH WORKING POC
D-Link DIR-823X Firmware 20250416 - http_casswd Command Injection
An issue was discovered in DIR-823 firmware 20250416. There is an RCE vulnerability in the set_cassword settings interface, as the http_casswd parameter is not filtered by '&'to allow injection of reverse connection commands.
CVSS 8.8