Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-8037 · Progress LoadMaster Command Injection Vulnerability · Added 2026-08-07 · Due 2026-08-10CISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08

Vendors · belden

belden

· 8 Critical

Total CVEs

32

Critical

8

Products

208

Search All CVEs →

32

Products (208)

hirschmann hios14 CVEshirschmann eagle3012 CVEshirschmann rail switch power lite12 CVEshirschmann rail switch power smart12 CVEshirschmann eagle2012 CVEshirschmann msp3211 CVEshirschmann msp4011 CVEshirschmann rspe3211 CVEshirschmann dragon mach400011 CVEshirschmann dragon mach450011 CVEshirschmann rspe3511 CVEshirschmann rspe3011 CVEshirschmann rsp3511 CVEshirschmann rsp3011 CVEshirschmann red2511 CVEshirschmann eagle one11 CVEshirschmann ees2011 CVEshirschmann ees2511 CVEshirschmann eesx2011 CVEshirschmann eesx3011 CVEshirschmann grs102011 CVEshirschmann grs103011 CVEshirschmann grs104211 CVEshirschmann grs112011 CVEshirschmann grs113011 CVEshirschmann grs114211 CVEshirschmann rspe3711 CVEshirschmann octopus os311 CVEshirschmann msp3011 CVEsgarrettcom magnum dx940e11 CVEsgarrettcom magnum dx940e firmware11 CVEshirschmann rsp2011 CVEshirschmann rsp2511 CVEstofino xenon security appliance9 CVEstofino xenon security appliance firmware9 CVEstofino argon fa-tsa-220-tx\/tx firmware6 CVEstofino argon fa-tsa-100-tx\/tx firmware6 CVEstofino argon fa-tsa-100-tx\/tx6 CVEseagle 20 tofino 943 987-505-mm\/mm firmware6 CVEseagle 20 tofino 943 987-501-tx\/tx6 CVEseagle 20 tofino 943 987-501-tx\/tx firmware6 CVEstofino argon fa-tsa-220-tx\/tx6 CVEstofino argon fa-tsa-220-tx\/mm firmware6 CVEstofino argon fa-tsa-220-tx\/mm6 CVEstofino argon fa-tsa-220-mm\/tx firmware6 CVEseagle 20 tofino 943 987-502 -tx\/mm6 CVEseagle 20 tofino 943 987-502 -tx\/mm firmware6 CVEseagle 20 tofino 943 987-504-mm\/tx6 CVEseagle 20 tofino 943 987-504-mm\/tx firmware6 CVEseagle 20 tofino 943 987-505-mm\/mm6 CVEstofino argon fa-tsa-220-mm\/mm firmware6 CVEstofino argon fa-tsa-220-mm\/tx6 CVEstofino argon fa-tsa-220-mm\/mm6 CVEshirschmann octopus 24m5 CVEshirschmann octopus 24m-8 poe5 CVEshirschmann octopus 24m-train5 CVEshirschmann octopus 24m-train-bp5 CVEshirschmann octopus 5tx eec5 CVEshirschmann octopus 8m5 CVEshirschmann octopus 8m-6poe5 CVEshirschmann octopus 8m-8poe5 CVEshirschmann octopus 8m-train5 CVEshirschmann octopus 8m-train-bp5 CVEshirschmann octopus 8tx-eec5 CVEshirschmann octopus 8tx poe-eec5 CVEshirschmann octopus os20-000900t5t5tafbhh5 CVEshirschmann octopus os20-000900t5t5tnebhh5 CVEshirschmann octopus os20-0010001m1mtrephh5 CVEshirschmann octopus os20-0010001s1strephh5 CVEshirschmann octopus os20-0010004m4mtrephh5 CVEshirschmann octopus os20-0010004s4strephh5 CVEshirschmann octopus os20-001000t5t5tafuhb5 CVEshirschmann octopus os20-001000t5t5tneuhb5 CVEshirschmann octopus os24-080900t5t5tffbhh5 CVEshirschmann octopus os24-080900t5t5tnebhh5 CVEshirschmann octopus os24-081000t5t5tffuhb5 CVEshirschmann octopus os24-081000t5t5tneuhb5 CVEshirschmann octopus os305 CVEshirschmann octopus os30-0008021a1atrephh5 CVEshirschmann octopus os30-0008021b1btrephh5 CVEshirschmann octopus os30-0008024a4atrephh5 CVEshirschmann octopus os30-0008024b4btrephh5 CVEshirschmann octopus os32-080802o6o6tpephh5 CVEshirschmann octopus os32-080802t6t6tpephh5 CVEshirschmann octopus os32-081602o6o6tpephh5 CVEshirschmann octopus os32-081602t6t6tpephh5 CVEshirschmann octopus os345 CVEshirschmann octopus os3x-xx16xxx5 CVEshirschmann octopus os3x-xx24xxx5 CVEshirschmann rs20-0900mmm2tdau5 CVEshirschmann rs20-0900nnm4tdau5 CVEshirschmann rs20-0900vvm2tdau5 CVEshirschmann rs20-1600l2l2sdau5 CVEshirschmann rs20-1600l2m2sdau5 CVEshirschmann rs20-1600l2s2sdau5 CVEshirschmann rs20-1600l2t1sdau5 CVEshirschmann rs20-1600m2m2sdau5 CVEshirschmann rs20-1600m2t1sdau5 CVEshirschmann rs20-1600s2m2sdau5 CVEshirschmann rs20-1600s2s2sdau5 CVEshirschmann rs20-1600s2t1sdau5 CVEshirschmann rsb20-0800m2m2saab5 CVEshirschmann rsb20-0800m2m2saabe5 CVEshirschmann rsb20-0800m2m2taab5 CVEshirschmann rsb20-0800m2m2taabe5 CVEshirschmann rsb20-0800s2s2saab5 CVEshirschmann rsb20-0800s2s2saabe5 CVEshirschmann rsb20-0800s2s2taab5 CVEshirschmann rsb20-0800s2s2taabe5 CVEshirschmann rsb20-0800t1t1saab5 CVEshirschmann rsb20-0800t1t1saabe5 CVEshirschmann rsb20-0800t1t1taab5 CVEshirschmann rsb20-0800t1t1taabe5 CVEshirschmann rsb20-0900m2ttsaab5 CVEshirschmann rsb20-0900m2ttsaabe5 CVEshirschmann rsb20-0900m2tttaab5 CVEshirschmann rsb20-0900m2tttaabe5 CVEshirschmann rsb20-0900mmm2saab5 CVEshirschmann rsb20-0900mmm2saabe5 CVEshirschmann rsb20-0900mmm2taab5 CVEshirschmann rsb20-0900mmm2taabe5 CVEshirschmann rsb20-0900s2ttsaab5 CVEshirschmann rsb20-0900s2ttsaabe5 CVEshirschmann rsb20-0900s2tttaab5 CVEshirschmann rsb20-0900s2tttaabe5 CVEshirschmann rsb20-0900vvm2saab5 CVEshirschmann rsb20-0900vvm2saabe5 CVEshirschmann rsb20-0900vvm2taab5 CVEshirschmann rsb20-0900vvm2taabe5 CVEshirschmann rsb20-0900zzz6saab5 CVEshirschmann rsb20-0900zzz6saabe5 CVEshirschmann rsb20-0900zzz6taabe5 CVEshirschmann rsb20-0900zzz6taab5 CVEshirschmann m1-8mm-sc5 CVEshirschmann m1-8sfp5 CVEshirschmann m1-8sm-sc5 CVEshirschmann m1-8tp-rj455 CVEshirschmann mach102-24tp-f5 CVEshirschmann mach102-24tp-fr5 CVEshirschmann mach102-8tp5 CVEshirschmann mach102-8tp-f5 CVEshirschmann mach102-8tp-fr5 CVEshirschmann mach102-8tp-r5 CVEshirschmann mach104-16tx-poep5 CVEshirschmann mach104-16tx-poep-l3p5 CVEshirschmann mach104-16tx-poep -e5 CVEshirschmann mach104-16tx-poep -e-l3p5 CVEshirschmann mach104-16tx-poep -r5 CVEshirschmann mach104-16tx-poep -r-l3p5 CVEshirschmann mach104-16tx-poep \+2x5 CVEshirschmann mach104-16tx-poep \+2x-l3p5 CVEshirschmann mach104-16tx-poep \+2x -e5 CVEshirschmann mach104-16tx-poep \+2x -e-l3p5 CVEshirschmann mach104-16tx-poep \+2x -r5 CVEshirschmann mach104-16tx-poep \+2x -r-l3p5 CVEshirschmann mach104-20tx-f5 CVEshirschmann mach104-20tx-f-4poe5 CVEshirschmann mach104-20tx-f-l3p5 CVEshirschmann mach104-20tx-fr5 CVEshirschmann mach104-20tx-fr-l3p5 CVEshirschmann mach4002-24g-l2p5 CVEshirschmann mach4002-24g-l3e5 CVEshirschmann mach4002-24g-l3p5 CVEshirschmann mach4002-24g\+3x-l2p5 CVEshirschmann mach4002-24g\+3x-l3e5 CVEshirschmann mach4002-24g\+3x-l3p5 CVEshirschmann mach4002-48g-l2p5 CVEshirschmann mach4002-48g-l3e5 CVEshirschmann mach4002-48g-l3p5 CVEshirschmann mach4002-48g\+3x-l2p5 CVEshirschmann mach4002-48g\+3x-l3e5 CVEshirschmann mach4002-48g\+3x-l3p5 CVEshirschmann ms20-0800eccp5 CVEshirschmann ms20-0800saae5 CVEshirschmann ms20-0800saap5 CVEshirschmann ms20-1600eccp5 CVEshirschmann ms20-1600saae5 CVEshirschmann ms20-1600saap5 CVEshirschmann ms30-0802saae5 CVEshirschmann ms30-0802saap5 CVEshirschmann ms30-1602saae5 CVEshirschmann octopus 16m5 CVEshirschmann octopus 16m-8poe5 CVEshirschmann octopus 16m-train5 CVEshirschmann octopus 16m-train-bp5 CVEshirschmann rsr205 CVEshirschmann rsr305 CVEshirschmann prp redbox1 CVEshirschmann octopus1 CVEshirschmann mice switch power1 CVEshirschmann l3p1 CVEshirschmann bat-c21 CVEshios switch1 CVEshisecos1 CVEsppc 2k05x1 CVEsppc 2k05x firmware1 CVEshirschmann l3e1 CVEshirschmann l2p1 CVEshirschmann l2e1 CVEshirschmann l2b1 CVEshirschmann hisecos1 CVEshirschmann greyhound swtich1 CVEshirschmann firmware1 CVEshirschmann embedded ethernet switch extended1 CVEshirschmann embedded ethernet switch1 CVEshirschmann bat-c2 firmware1 CVEshirschmann rail switch power enhanced1 CVEshirschmann rail switch power1 CVEs

Recent Vulnerabilities

View all 32
CVE-2025-15620HIGH 8.6

HiOS Switch Platform versions 09.1.00 through 09.4.04 and 10.0.00 through 10.3.00 contain a denial-of-service vulnerability in the web interface that allows remote attackers to reboot the affected device by sending a malicious HTTP GET request to a specific endpoint. Attackers can trigger an uncontrolled reboot condition through crafted HTTP requests to cause service disruption and unavailability of the switch.

CVE-2025-70545MEDIUM 6.1

A stored cross-site scripting (XSS) vulnerability exists in the web management interface of the PPC (Belden) ONT 2K05X router running firmware v1.1.9_206L. The Common Gateway Interface (CGI) component improperly handles user-supplied input, allowing a remote, unauthenticated attacker to inject arbitrary JavaScript that is persistently stored and executed when the affected interface is accessed.

CVE-2022-40282HIGH 8.8

The web server of Hirschmann BAT-C2 before 09.13.01.00R04 allows authenticated command injection. This allows an authenticated attacker to pass commands to the shell of the system because the dir parameter of the FsCreateDir Ajax function is not sufficiently sanitized. The vendor's ID is BSECV-2022-21.

CVE-2021-30066MEDIUM 6.8

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an arbitrary firmware image can be loaded because firmware signature verification (for a USB stick) can be bypassed. NOTE: this issue exists because of an incomplete fix of CVE-2017-11400.

CVE-2021-30065HIGH 7.5

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, crafted ModBus packets can bypass the ModBus enforcer. NOTE: this issue exists because of an incomplete fix of CVE-2017-11401.

CVE-2021-30064CRITICAL 9.8

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, an SSH login can succeed with hardcoded default credentials (if the device is in the uncommissioned state).

CVE-2021-30063HIGH 7.5

On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafted OPC packets can cause an OPC enforcer denial of service.

CVE-2021-30062HIGH 7.5

On Schneider Electric ConneXium Tofino OPCLSM TCSEFM0000 before 03.23 and Belden Tofino Xenon Security Appliance, crafted OPC packets can bypass the OPC enforcer.

CVE-2021-30061MEDIUM 6.8

On Schneider Electric ConneXium Tofino Firewall TCSEFEA23F3F22 before 03.23, TCSEFEA23F3F20/21, and Belden Tofino Xenon Security Appliance, physically proximate attackers can execute code via a crafted file on a USB stick.

CVE-2021-27734CRITICAL 9.8

Hirschmann HiOS 07.1.01, 07.1.02, and 08.1.00 through 08.5.xx and HiSecOS 03.3.00 through 03.5.01 allow remote attackers to change the credentials of existing users.

CVE-2020-9307MEDIUM 6.5

Hirschmann OS2, RSP, and RSPE devices before HiOS 08.3.00 allow a denial of service. An unauthenticated, adjacent attacker can cause an infinite loop on one of the HSR ring ports of the device. This effectively breaks the redundancy of the HSR ring. If the attacker can perform the same attack on a second device, the ring is broken into two parts (thus disrupting communication between devices in the different parts).

CVE-2020-6994CRITICAL 9.8

A buffer overflow vulnerability was found in some devices of Hirschmann Automation and Control HiOS and HiSecOS. The vulnerability is due to improper parsing of URL arguments. An attacker could exploit this vulnerability by specially crafting HTTP requests to overflow an internal buffer. The following devices using HiOS Version 07.0.02 and lower are affected: RSP, RSPE, RSPS, RSPL, MSP, EES, EES, EESX, GRS, OS, RED. The following devices using HiSecOS Version 03.2.00 and lower are affected: EAGLE20/30.

CVE-2019-12262CRITICAL 9.8

Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and 7 has Incorrect Access Control in the RARP client component. IPNET security vulnerability: Handling of unsolicited Reverse ARP replies (Logical Flaw).

CVE-2019-12261CRITICAL 9.8

Wind River VxWorks 6.7 though 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 3 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion during connect() to a remote host.

CVE-2019-12260CRITICAL 9.8

Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the TCP component (issue 2 of 4). This is an IPNET security vulnerability: TCP Urgent Pointer state confusion caused by a malformed TCP AO option.

CVE-2019-12258HIGH 7.5

Wind River VxWorks 6.6 through vx7 has Session Fixation in the TCP component. This is a IPNET security vulnerability: DoS of TCP connection via malformed TCP options.

CVE-2019-12255CRITICAL 9.8

Wind River VxWorks has a Buffer Overflow in the TCP component (issue 1 of 4). This is a IPNET security vulnerability: TCP Urgent Pointer = 0 that leads to an integer underflow.

CVE-2019-12265MEDIUM 5.3

Wind River VxWorks 6.5, 6.6, 6.7, 6.8, 6.9.3 and 6.9.4 has a Memory Leak in the IGMPv3 client component. There is an IPNET security vulnerability: IGMP Information leak via IGMPv3 specific membership report.

CVE-2019-12263HIGH 8.1

Wind River VxWorks 6.9.4 and vx7 has a Buffer Overflow in the TCP component (issue 4 of 4). There is an IPNET security vulnerability: TCP Urgent Pointer state confusion due to race condition.

CVE-2019-12259HIGH 7.5

Wind River VxWorks 6.6, 6.7, 6.8, 6.9 and vx7 has an array index error in the IGMPv3 client component. There is an IPNET security vulnerability: DoS via NULL dereference in IGMP parsing.

CVE-2019-12257HIGH 8.8

Wind River VxWorks 6.6 through 6.9 has a Buffer Overflow in the DHCP client component. There is an IPNET security vulnerability: Heap overflow in DHCP Offer/ACK parsing inside ipdhcpc.

CVE-2019-12256CRITICAL 9.8

Wind River VxWorks 6.9 and vx7 has a Buffer Overflow in the IPv4 component. There is an IPNET security vulnerability: Stack overflow in the parsing of IPv4 packets’ IP options.

CVE-2019-12264HIGH 7.1

Wind River VxWorks 6.6, 6.7, 6.8, 6.9.3, 6.9.4, and Vx7 has Incorrect Access Control in IPv4 assignment by the ipdhcpc DHCP client component.

CVE-2018-5471

A Cleartext Transmission of Sensitive Information issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. A cleartext transmission of sensitive information vulnerability in the web interface has been identified, which may allow an attacker to obtain sensitive information through a successful man-in-the-middle attack.

CVE-2018-5469

An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An improper restriction of excessive authentication vulnerability in the web interface has been identified, which may allow an attacker to brute force authentication.