SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

48 results for “cwe-840” · 1.73 s · cached

Facets · 3 entity types

35 CVE8 CWE5 CAPEC
CAPEC-680CAPEC

Exploitation of Improperly Controlled Registers

Metadata: detailed CAPEC pattern, status draft, likelihood medium, severity high. Underlying weaknesses: CWE-1224, CWE-1231, CWE-1233, CWE-1262, CWE-1283. Related CAPEC patterns: [object Object], [ob…

Detailed
Match for cwe-840
CWE-1187CWE

DEPRECATED: Use of Uninitialized Resource

This entry has been deprecated because it was a duplicate of CWE-908. All content has been transferred to CWE-908.

Match for cwe-840
CVE-2025-44886CVE

CVE-2025-44886

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_mgmt_Rules_Edit_postcontains function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CWE-264CWE

CWE-264: Permissions, Privileges, and Access Controls

Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.

Match for cwe-840
CVE-2025-44888CVE

CVE-2025-44888

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_globalSetting_post function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CVE-2025-44885CVE

CVE-2025-44885

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_remote_engineId_add_post function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CVE-2025-14737CVE

CVE-2025-14737

Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbitrary commands.This issue affects: ≤ WA850RE V2_160527, ≤ WA850RE V3_160922.

CVSS 8.0EPSS 0.9%
Match for cwe-840
CWE-218CWE

DEPRECATED: Failure to provide confidentiality for stored data

This weakness has been deprecated because it was a duplicate of CWE-493. All content has been transferred to CWE-493.

Match for cwe-840
CWE-1324CWE

DEPRECATED: Sensitive Information Accessible by Physical Probing of JTAG Interface

This entry has been deprecated because it was at a lower level of abstraction than supported by CWE. All relevant content has been integrated into CWE-319.

Match for cwe-840
CVE-2025-44884CVE

CVE-2025-44884

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CAPEC-681CAPEC

Exploitation of Improperly Controlled Hardware Security Identifiers

Metadata: detailed CAPEC pattern, status draft, likelihood medium, severity very high. Underlying weaknesses: CWE-1259, CWE-1267, CWE-1270, CWE-1294, CWE-1302. Related CAPEC patterns: [object Object]…

Detailed
Match for cwe-840
CVE-2025-44883CVE

CVE-2025-44883

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_serverEdit_post function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CVE-2025-44890CVE

CVE-2025-44890

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv3_add_post function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CVE-2025-4340CVE

CVE-2025-4340

A vulnerability classified as critical has been found in D-Link DIR-890L and DIR-806A1 up to 100CNb11/108B03. Affected is the function sub_175C8 of the file /htdocs/soap.cgi. The manipulation leads t…

CVSS 9.8EPSS 5.3%
Match for cwe-840
CVE-2025-44896CVE

CVE-2025-44896

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_bindEdit_post function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CVE-2025-6328CVE

CVE-2025-6328

A vulnerability was found in D-Link DIR-815 1.01. It has been declared as critical. This vulnerability affects the function sub_403794 of the file hedwig.cgi. The manipulation leads to stack-based bu…

CVSS 8.8EPSS 1.2%
Match for cwe-840
CVE-2025-44891CVE

CVE-2025-44891

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_add_post function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CVE-2025-44898CVE

CVE-2025-44898

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the theauthName parameter in the web_aaa_loginAuthlistEdit function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CVE-2025-41270CVE

CVE-2025-41270

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in versio…

CVSS 9.8EPSS 1.4%waterfall-security
Match for cwe-840
CWE-423CWE

DEPRECATED: Proxied Trusted Channel

This entry has been deprecated because it was a duplicate of CWE-441. All content has been transferred to CWE-441.

Match for cwe-840
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.