▲ ▼ ☑ ✕ ⚖
Multiple Critical Remote-Code-Execution Vulnerabilities Disclosed
Between September 14–15, 2026, multiple critical buffer-overflow and command-injection vulnerabilities with public exploit code were disclosed in router firmware (Totolink A3002MU, D-Link DI-8300), a timecard application (TREXOM TrxTimeATTENDANCE), and a mesh platform (pig-mesh pig). All allow unauthenticated remote code execution; no patches were available as of the latest report.
10 reports other
All coverage
CVE-2026-90606: CRITICAL buffer overflow in Totolink A3002MU (Hh-B20211125.1046). Remote attackers can exploit static_ipv6 in /boafrm/formIpv6Setup. Exploit is public — review device exposure now. https:// radar.offseq.com/threat/cve-20 26-90606-buffer-overflow-in-totolink-a3002mu-ff1e560ec5dedad6 # OffSeq # CVE202690606 # RouterSecurity # NetSec
CVE-2026-90608: Totolink A3002MU routers have a CRITICAL buffer overflow (CVSS 9.4) in /boafrm/formPortFw. Exploit code is public; RCE possible. No patch — restrict external access & monitor vendor updates. https:// radar.offseq.com/threat/cve-20 26-90608-buffer-overflow-in-totolink-a3002mu-43328ea907451224 # OffSeq # CVE202690608 # RouterSecurity
Totolink A3002MU routers hit by CRITICAL (CVSS 9.4) buffer overflow (CVE-2026-90607) in formNewSchedule. Public exploit code available. Restrict remote access & monitor systems until a patch is released. https:// radar.offseq.com/threat/cve-20 26-90607-buffer-overflow-in-totolink-a3002mu-f5be31acbfac3e1f # OffSeq # CVE202690607 # RouterSecurity # Infosec
CVE-2026-90606: HIGH-severity buffer overflow in Totolink A3002MU Hh-B20211125.1046 (boa/formIpv6Setup). Public exploit disclosed. RCE or DoS possible. Restrict access & monitor IPv6 setup. No patch yet. https:// radar.offseq.com/threat/a-secu rity-vulnerability-has-been-detected-in-totolink-a3002mu-hh-b202111251046-cve-2026-90606-6a6dad4a128a1845 # OffSeq # Vuln # IoTSecurity # BufferOverflow
D-Link DWR-M921 v1.1.52 is vulnerable to CRITICAL OS command injection (CVE-2026-90703, CVSS 9.4). No patch yet, public exploit out. Restrict access & monitor logs. Details: https:// radar.offseq.com/threat/cve-20 26-90703-os-command-injection-in-d-link-dwr-m921-f9739a3ef4495656 # OffSeq # CVE # RouterSecurity # Infosec
EFM ipTIME C200E v1.094 suffers CRITICAL OS command injection (CVE-2026-90847, CVSS 9.4) via iux_set.cgi. Remotely exploitable, public exploit available. Restrict device access and monitor. https:// radar.offseq.com/threat/cve-20 26-90847-os-command-injection-in-efm-iptime-c200e-1c30057b126bbbf4 # OffSeq # Vulnerability # IoTSecurity # CVE
Stack-based buffer overflow (CVE-2026-91001, CVSS 9.4) in D-Link DI-8400 (16.07) exposes devices to RCE. Exploit code is public. Restrict management access until fix. Details: https:// radar.offseq.com/threat/cve-20 26-91001-stack-based-buffer-overflow-in-d-link-di-8400-abc2e3e858f255b9 # OffSeq # CVE202691001 # IoTSecurity # Vulnerability
D-Link DI-8300 (fw 16.07) hit by CRITICAL stack buffer overflow (CVE-2026-91003) in /rzgl.asp — remote RCE possible, public exploit code out. Restrict access & monitor traffic until patch. https:// radar.offseq.com/threat/cve-20 26-91003-stack-based-buffer-overflow-in-d-link-di-8300-ce23f2734338a347 # OffSeq # CVE202691003 # DLink # Security
CVE-2026-89308 in TREXOM TrxTimeATTENDANCE (v1.0.5 – 1.9.5): CRITICAL OS command injection in ping.php allows unauthenticated RCE. Remediate ASAP. https:// radar.offseq.com/threat/cve-20 26-89308-cwe-78-improper-neutralization-of-special-elements-used-in-an-os-command-os-command-8f863d468f1bf361 # OffSeq # CVE202689308 # infosec # vuln # remediation
pig-mesh pig <4.1.0 hit by CRITICAL vuln (CVE-2026-91995, CVSS 9.3): remote attackers can reset any account password — admin included — via /register/password auth bypass. Restrict access & monitor logs while awaiting patch. https:// radar.offseq.com/threat/cve-20 26-91995-unverified-password-change-in-pig-mesh-pig-6a0b879ab4cc0e5c # OffSeq # vulnerability # CVE # infosec