Skip to content
Signals
NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07NVD · CVE-2026-64604 · In the Linux kernel, the following vulnerability has been resolved: KVM: VMX: Grab vmcs12 on CR8 interception update iff vCPU is in guest mode When updating CR8NVD · CVE-2026-64603 · In the Linux kernel, the following vulnerability has been resolved: platform/x86: intel-hid: Protect ACPI notify handler against recursion Since commit e2ffcda1NVD · CVE-2026-64602 · In the Linux kernel, the following vulnerability has been resolved: iio: adc: spear: Initialize completion before requesting IRQ In the report from Jaeyoung ChuNVD · CVE-2026-64601 · In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor list on eachCISA KEV · CVE-2026-63077 · 9.8 · JetBrains TeamCity Deserialization of Untrusted Data Vulnerability · Added 2026-08-05 · Due 2026-08-08CISA KEV · CVE-2026-18556 · 7.4 · N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability · Added 2026-08-04 · Due 2026-08-07

Vendors · iodata

iodata

· 1 Critical

Total CVEs

35

Critical

1

Products

164

Search All CVEs →

35

Products (164)

ts-wrla firmware6 CVEsts-wrlp firmware6 CVEsts-wrla6 CVEsts-wrlp6 CVEswn-g300r35 CVEswn-g300r3 firmware5 CVEswn-ax1167gr firmware4 CVEsts-wptcam2 firmware4 CVEsts-wptcam24 CVEswn-ax1167gr4 CVEsts-ptcam\/poe firmware3 CVEsts-wptcam firmware3 CVEsts-ptcam3 CVEsts-ptcam\/poe3 CVEsts-wlce3 CVEsts-wrlc3 CVEsts-ptcam firmware3 CVEsts-wlc2 firmware3 CVEsts-wlce firmware3 CVEsts-wrlc firmware3 CVEsts-wrlp\/e3 CVEsts-wrlp\/e firmware3 CVEsts-wptcam3 CVEsts-wlc23 CVEswfs-sr03w firmware2 CVEshdl-a firmware2 CVEsrockdisk2 CVEsrockdisk firmware2 CVEsts-ptcam\/poe camera firmware2 CVEsts-ptcam\/poe camera2 CVEsts-ptcam camera2 CVEsts-ptcam camera firmware2 CVEsts-wlc2 camera2 CVEsts-wlc2 camera firmware2 CVEshdl-ah2 CVEswn-ac1167r2 CVEswn-ac1167r firmwre2 CVEsetx-r2 CVEshvl-at2 CVEshvl-ata2 CVEsetx-r firmware2 CVEshdl2-a firmware2 CVEsts-wptcam camera2 CVEsts-wptcam camera firmware2 CVEswn-g300r2 CVEswn-g300r firmware2 CVEshvl-a2 CVEshdl2-ah2 CVEswfs-sr012 CVEswfs-sr01 firmware2 CVEswfs-sr03k2 CVEswfs-sr03k firmware2 CVEswfs-sr03w2 CVEsts-wlcam\/v camera firmware1 CVEsts-wlcam camera1 CVEsts-wlcam camera firmware1 CVEsts-wlce camera1 CVEsts-wlce camera firmware1 CVEsts-wrlc camera1 CVEsts-wrlc camera firmware1 CVEswhg-ac17501 CVEswhg-ac1750 firmware1 CVEswhg-ac1750a1 CVEswhg-ac1750a firmware1 CVEswhg-ac1750al1 CVEswhg-ac1750al firmware1 CVEswhg-napg1 CVEswhg-napg firmware1 CVEswhg-napga1 CVEswhg-napga firmware1 CVEswhg-napgal1 CVEswhg-napgal firmware1 CVEswn-ac1167dgr1 CVEswn-ac1167dgr firmware1 CVEswn-ac1167gr1 CVEswn-ac1167gr firmware1 CVEswn-ac1300ex1 CVEswn-ac1300ex firmware1 CVEswn-ac1600dgr1 CVEswn-ac1600dgr firmware1 CVEswn-ac583rk1 CVEswn-ac583rk firmware1 CVEswn-ac583trk1 CVEswn-ac583trk firmware1 CVEswn-ag300dgr1 CVEswn-ag300dgr firmware1 CVEswn-ag750dgr1 CVEswn-ag750dgr firmware1 CVEswn-g300ex1 CVEswn-g300ex firmware1 CVEswn-g300r21 CVEswn-g300r2 firmware1 CVEswn-g300sr1 CVEswn-g300sr firmware1 CVEswn-g54\/r21 CVEswn-g54\/r2 firmware1 CVEswn-gdn\/r31 CVEswn-gdn\/r3-c1 CVEswn-gdn\/r3-s1 CVEswn-gdn\/r3-u1 CVEswn-gdn\/r3 firmware1 CVEswn-gx300gr1 CVEswn-gx300gr firmware1 CVEswnpr1167f1 CVEswnpr1167f firmware1 CVEswnpr1167g1 CVEswnpr1167g firmware1 CVEswnpr1750g1 CVEswnpr1750g firmware1 CVEswnpr2600g1 CVEsbx-vp11 CVEswnpr2600g firmware1 CVEsbx-vp1 firmware1 CVEsgv-ntx11 CVEsgv-ntx1 firmware1 CVEsgv-ntx21 CVEsgv-ntx2 firmware1 CVEshdl-a1 CVEshdl-a\/e1 CVEshdl-ah firmware1 CVEshdl-as1 CVEshdl-gt1 CVEshdl-gt firmware1 CVEshdl-gtr1 CVEshdl-gtr firmware1 CVEshdl-t1 CVEshdl-t firmware1 CVEshdl-xr1 CVEshdl-xr2u1 CVEshdl-xr2u firmware1 CVEshdl-xr2uw1 CVEshdl-xr2uw firmware1 CVEshdl-xr firmware1 CVEshdl-xrw1 CVEshdl-xrw firmware1 CVEshdl-xv1 CVEshdl-xv firmware1 CVEshdl-xvw1 CVEshdl-xvw firmware1 CVEshdl2-a1 CVEshdl2-a\/e1 CVEshdl2-ah firmware1 CVEshfas11 CVEshfas1 firmware1 CVEshls-c1 CVEshls-c firmware1 CVEshvl-a2.0 firmware1 CVEshvl-a3.0 firmware1 CVEshvl-a4.0 firmware1 CVEshvl-a firmware1 CVEshvl-at1.0s firmware1 CVEshvl-at2.0 firmware1 CVEshvl-at2.0a firmware1 CVEshvl-at3.0 firmware1 CVEshvl-at3.0a firmware1 CVEshvl-at4.0 firmware1 CVEshvl-at4.0a firmware1 CVEshvl-at firmware1 CVEshvl-ata firmware1 CVEshvl-s1 CVEshvl-s firmware1 CVEslan disk connect1 CVEslan disk connect firmware1 CVEsts-wlcam\/v camera1 CVEs

Recent Vulnerabilities

View all 35
CVE-2023-29805CRITICAL 9.8

WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function.

CVE-2023-29804HIGH 8.8

WFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function.

CVE-2019-19823HIGH 7.5

A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) stores cleartext administrative passwords in flash memory and in a file. This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.

CVE-2019-19822HIGH 7.5

A certain router administration interface (that includes Realtek APMIB 0.11f for Boa 0.94.14rc21) allows remote attackers to retrieve the configuration, including sensitive data (usernames and passwords). This affects TOTOLINK A3002RU through 2.0.0, A702R through 2.1.3, N301RT through 2.1.6, N302R through 3.4.0, N300RT through 3.4.0, N200RE through 4.0.0, N150RT through 3.4.0, and N100RE through 3.4.0; Rutek RTK 11N AP through 2019-12-12; Sapido GR297n through 2019-12-12; CIK TELECOM MESH ROUTER through 2019-12-12; KCTVJEJU Wireless AP through 2019-12-12; Fibergate FGN-R2 through 2019-12-12; Hi-Wifi MAX-C300N through 2019-12-12; HCN MAX-C300N through 2019-12-12; T-broad GN-866ac through 2019-12-12; Coship EMTA AP through 2019-12-12; and IO-Data WN-AC1167R through 2019-12-12.

CVE-2018-0663

Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver.1.09.04 and earlier) use hardcoded credentials which may allow an remote authenticated attacker to execute arbitrary OS commands on the device via unspecified vector.

CVE-2018-0662

Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver.1.09.04 and earlier) allow an attacker on the same network segment to add malicious files on the device and execute arbitrary code.

CVE-2018-0661

Multiple I-O DATA network camera products (TS-WRLP firmware Ver.1.09.04 and earlier, TS-WRLA firmware Ver.1.09.04 and earlier, TS-WRLP/E firmware Ver.1.09.04 and earlier) allow an attacker on the same network segment to bypass access restriction to add files on a specific directory that may result in executing arbitrary OS commands/code or information including credentials leakage or alteration.

CVE-2018-0512

Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands via unspecified vectors.

CVE-2017-10875

I-O DATA DEVICE LAN DISK Connect Ver2.02 and earlier allows an attacker to cause a denial of service in the application via unspecified vectors.

CVE-2017-2283

WN-G300R3 firmware version 1.0.2 and earlier uses hardcoded credentials which may allow an attacker that can access the device to execute arbitrary code on the device.

CVE-2017-2282

Buffer overflow in WN-AX1167GR firmware version 3.00 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.

CVE-2017-2281

WN-AX1167GR firmware version 3.00 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.

CVE-2017-2280

WN-AX1167GR firmware version 3.00 and earlier uses hardcoded credentials which may allow an attacker that can access the device to execute arbitrary code on the device.

CVE-2017-2223

Cross-site request forgery (CSRF) vulnerability in TS-WPTCAM, TS-PTCAM, TS-PTCAM/POE, TS-WLC2, TS-WLCE, TS-WRLC firmware version 1.19 and earlier and TS-WPTCAM2 firmware version 1.01 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

CVE-2016-7820

Buffer overflow in I-O DATA DEVICE TS-WRLP firmware version 1.01.02 and earlier and TS-WRLA firmware version 1.01.02 and earlier allows an attacker with administrator rights to cause a denial-of-service (DoS) or execute arbitrary code via unspecified vectors.

CVE-2016-7819

I-O DATA DEVICE TS-WRLP firmware version 1.01.02 and earlier and TS-WRLA firmware version 1.01.02 and earlier allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vectors.

CVE-2016-7814

I-O DATA DEVICE TS-WRLP firmware version 1.00.01 and earlier and TS-WRLA firmware version 1.00.01 and earlier allow remote attackers to obtain authentication credentials via unspecified vectors.

CVE-2016-7807

I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to bypass access restriction to access data on storage devices inserted into the product via unspecified vectors.

CVE-2016-7806

I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors.

CVE-2017-2148

Cross-site scripting vulnerability in WN-AC1167GR firmware version 1.04 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2017-2142

Buffer overflow in WN-G300R3 firmware Ver.1.03 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

CVE-2017-2141

WN-G300R3 firmware 1.03 and earlier allows attackers with administrator rights to execute arbitrary OS commands via unspecified vectors.

CVE-2017-2113

Buffer overflow in TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware version 1.18 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

CVE-2017-2112

TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware version 1.18 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

CVE-2017-2111

HTTP header injection vulnerability in TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware version 1.18 and earlier may allow a remote attackers to display false information.