Writeup Exploits

64,853 exploits tracked across all sources.

Sort: Activity Stars
CVE-2025-15048 WRITEUP HIGH
Tenda WH450 1.0.0.18 - OS Command Injection via CheckTools ipaddress Parameter
A vulnerability was determined in Tenda WH450 1.0.0.18. This impacts an unknown function of the file /goform/CheckTools of the component HTTP Request Handler. Executing a manipulation of the argument ipaddress can lead to command injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
CVSS 7.3
CVE-2025-15047 WRITEUP CRITICAL
Tenda WH450 1.0.0.18 - Stack-based Buffer Overflow via PPTPDClient Username Parameter
A vulnerability was found in Tenda WH450 1.0.0.18. This affects an unknown function of the file /goform/PPTPDClient of the component HTTP Request Handler. Performing a manipulation of the argument Username results in stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made public and could be used.
CVSS 9.8
CVE-2025-15046 WRITEUP CRITICAL
Tenda WH450 1.0.0.18 - Stack-based Buffer Overflow via PPTPClient netmsk Parameter
A vulnerability has been found in Tenda WH450 1.0.0.18. The impacted element is an unknown function of the file /goform/PPTPClient of the component HTTP Request Handler. Such manipulation of the argument netmsk leads to stack-based buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS 9.8
CVE-2025-15045 WRITEUP CRITICAL
Tenda WH450 1.0.0.18 - Stack-based Buffer Overflow via Natlimit Page Parameter
A flaw has been found in Tenda WH450 1.0.0.18. The affected element is an unknown function of the file /goform/Natlimit of the component HTTP Request Handler. This manipulation of the argument page causes stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been published and may be used.
CVSS 9.8
CVE-2025-15044 WRITEUP CRITICAL
Tenda WH450 1.0.0.18 - Stack-based Buffer Overflow via NatStaticSetting Page Parameter
A vulnerability was detected in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/NatStaticSetting. The manipulation of the argument page results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.
CVSS 9.8
CVE-2025-15010 WRITEUP CRITICAL
Tenda WH450 1.0.0.18 - Stack-based Buffer Overflow via SafeUrlFilter Page Parameter
A vulnerability has been found in Tenda WH450 1.0.0.18. This issue affects some unknown processing of the file /goform/SafeUrlFilter. The manipulation of the argument page leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
CVSS 9.8
CVE-2025-15008 WRITEUP HIGH
Tenda WH450 1.0.0.18 - Stack-Based Buffer Overflow via L7Port HTTP Request Handler
A vulnerability was detected in Tenda WH450 1.0.0.18. This affects an unknown part of the file /goform/L7Port of the component HTTP Request Handler. Performing a manipulation of the argument page results in stack-based buffer overflow. The attack may be initiated remotely. The exploit is now public and may be used.
CVSS 7.3
CVE-2025-15007 WRITEUP CRITICAL
Tenda WH450 1.0.0.18 - Stack-based Buffer Overflow via L7Im Page Argument
A security vulnerability has been detected in Tenda WH450 1.0.0.18. Affected by this issue is some unknown functionality of the file /goform/L7Im of the component HTTP Request Handler. Such manipulation of the argument page leads to stack-based buffer overflow. The attack can be launched remotely. The exploit has been disclosed publicly and may be used.
CVSS 9.8
CVE-2025-15006 WRITEUP CRITICAL
Tenda WH450 1.0.0.18 - Stack-based Buffer Overflow via CheckTools ipaddress Parameter
A weakness has been identified in Tenda WH450 1.0.0.18. Affected by this vulnerability is an unknown functionality of the file /goform/CheckTools of the component HTTP Request Handler. This manipulation of the argument ipaddress causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks.
CVSS 9.8
CVE-2025-14995 WRITEUP HIGH
Tenda FH1201 1.2.0.14(408) - Stack-based Buffer Overflow via SetIpBind Page Argument
A vulnerability has been found in Tenda FH1201 1.2.0.14(408). Affected is the function sprintf of the file /goform/SetIpBind. Such manipulation of the argument page leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed to the public and may be used.
CVSS 8.8
CVE-2025-14994 WRITEUP HIGH
Tenda FH1201 and FH1206 1.2.0.14(408)/1.2.0.8(8155) - Stack-based Buffer Overflow via webSiteId Argument
A flaw has been found in Tenda FH1201 and FH1206 1.2.0.14(408)/1.2.0.8(8155). This impacts the function strcat of the file /goform/webtypelibrary of the component HTTP Request Handler. This manipulation of the argument webSiteId causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been published and may be used.
CVSS 8.8
CVE-2025-14993 WRITEUP HIGH
Tenda AC18 15.03.05.05 - Stack-based Buffer Overflow via SetDlnaCfg scanList Parameter
A vulnerability was detected in Tenda AC18 15.03.05.05. This affects the function sprintf of the file /goform/SetDlnaCfg of the component HTTP Request Handler. The manipulation of the argument scanList results in stack-based buffer overflow. The attack can be executed remotely. The exploit is now public and may be used.
CVSS 8.8
CVE-2025-14992 WRITEUP HIGH
Tenda AC18 15.03.05.05 - Stack-based Buffer Overflow via mac Argument in GetParentControlInfo
A security vulnerability has been detected in Tenda AC18 15.03.05.05. The impacted element is the function strcpy of the file /goform/GetParentControlInfo of the component HTTP Request Handler. The manipulation of the argument mac leads to stack-based buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
CVSS 8.8
CVE-2025-14665 WRITEUP CRITICAL
Tenda WH450 1.0.0.18 - Buffer Overflow
A security flaw has been discovered in Tenda WH450 1.0.0.18. Impacted is an unknown function of the file /goform/DhcpListClient of the component HTTP Request Handler. The manipulation of the argument page results in stack-based buffer overflow. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
CVSS 9.8
CVE-2025-11444 WRITEUP HIGH
TOTOLINK N600R <4.3.0cu.7866_B20220506 - Buffer Overflow
A security vulnerability has been detected in TOTOLINK N600R up to 4.3.0cu.7866_B20220506. This impacts the function setWiFiBasicConfig of the file /cgi-bin/cstecgi.cgi of the component HTTP Request Handler. Such manipulation of the argument wepkey leads to buffer overflow. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used.
CVSS 8.8
CVE-2025-60424 WRITEUP HIGH
Nagios Fusion <2024R2 - Auth Bypass
A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a bruteforce attack.
CVSS 7.6
CVE-2025-60424 WRITEUP HIGH
Nagios Fusion <2024R2 - Auth Bypass
A lack of rate limiting in the OTP verification component of Nagios Fusion v2024R1.2 and v2024R2 allows attackers to bypass authentication via a bruteforce attack.
CVSS 7.6
CVE-2025-60425 WRITEUP HIGH
Nagios Fusion <2024R2 - Session Hijacking
Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session hijacking attack.
CVSS 8.6
CVE-2025-60425 WRITEUP HIGH
Nagios Fusion <2024R2 - Session Hijacking
Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session hijacking attack.
CVSS 8.6
CVE-2025-60455 WRITEUP HIGH
Modular Max Serve <25.6 - Code Injection
Unsafe Deserialization vulnerability in Modular Max Serve before 25.6, specifically when the "--experimental-enable-kvcache-agent" feature is used allowing attackers to execute arbitrary code.
CVSS 8.4
CVE-2025-60537 WRITEUP MEDIUM
kafka-ui 0.6.0-0.7.2 - Remote Code Execution via CustomSerdeLoader Input Validation
Improper input validation in the component /kafka/ui/serdes/CustomSerdeLoader.java of kafka-ui v0.6.0 to v0.7.2 allows attackers to execute arbitrary code via supplying crafted data.
CVSS 6.5
CVE-2025-60537 WRITEUP MEDIUM
kafka-ui 0.6.0-0.7.2 - Remote Code Execution via CustomSerdeLoader Input Validation
Improper input validation in the component /kafka/ui/serdes/CustomSerdeLoader.java of kafka-ui v0.6.0 to v0.7.2 allows attackers to execute arbitrary code via supplying crafted data.
CVSS 6.5
CVE-2025-60536 WRITEUP HIGH
kafka-ui 0.6.0-0.7.2 - Denial of Service via Crafted Configuration File Upload
An issue in the Configure New Cluster interface of kafka-ui v0.6.0 to v0.7.2 allows attackers to cause a Denial of Service (DoS) via uploading a crafted configuration file.
CVSS 7.5
CVE-2025-60536 WRITEUP HIGH
kafka-ui 0.6.0-0.7.2 - Denial of Service via Crafted Configuration File Upload
An issue in the Configure New Cluster interface of kafka-ui v0.6.0 to v0.7.2 allows attackers to cause a Denial of Service (DoS) via uploading a crafted configuration file.
CVSS 7.5
CVE-2024-32030 WRITEUP HIGH
Kafka UI < 0.7.2 - Remote Code Execution via JMX Deserialization
Kafka UI is an Open-Source Web UI for Apache Kafka Management. Kafka UI API allows users to connect to different Kafka brokers by specifying their network address and port. As a separate feature, it also provides the ability to monitor the performance of Kafka brokers by connecting to their JMX ports. JMX is based on the RMI protocol, so it is inherently susceptible to deserialization attacks. A potential attacker can exploit this feature by connecting Kafka UI backend to its own malicious broker. This vulnerability affects the deployments where one of the following occurs: 1. dynamic.config.enabled property is set in settings. It's not enabled by default, but it's suggested to be enabled in many tutorials for Kafka UI, including its own README.md. OR 2. an attacker has access to the Kafka cluster that is being connected to Kafka UI. In this scenario the attacker can exploit this vulnerability to expand their access and execute code on Kafka UI as well. Instead of setting up a legitimate JMX port, an attacker can create an RMI listener that returns a malicious serialized object for any RMI call. In the worst case it could lead to remote code execution as Kafka UI has the required gadget chains in its classpath. This issue may lead to post-auth remote code execution. This is particularly dangerous as Kafka-UI does not have authentication enabled by default. This issue has been addressed in version 0.7.2. All users are advised to upgrade. There are no known workarounds for this vulnerability. These issues were discovered and reported by the GitHub Security lab and is also tracked as GHSL-2023-230.
CVSS 8.1