SEARCHSearch the cs-graph

CVE-#### · MITRE T#### · CWE-#### · ATLAS AML.T#### · D3-XX · compliance article references. Authored by Adam Lundqvist.

35 results for “cwe-840” · 1.77 s · cached

Facets · 1 entity types

35 CVEClear type filter
CVE-2025-44886CVE

CVE-2025-44886

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the byruleEditName parameter in the web_acl_mgmt_Rules_Edit_postcontains function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CVE-2025-44888CVE

CVE-2025-44888

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the stp_conf_name parameter in the web_stp_globalSetting_post function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CVE-2025-44885CVE

CVE-2025-44885

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the remote_ip parameter in the web_snmpv3_remote_engineId_add_post function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CVE-2025-14737CVE

CVE-2025-14737

Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to inject arbitrary commands.This issue affects: ≤ WA850RE V2_160527, ≤ WA850RE V3_160922.

CVSS 8.0EPSS 0.9%
Match for cwe-840
CVE-2025-44884CVE

CVE-2025-44884

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the web_sys_infoContact_post function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CVE-2025-44883CVE

CVE-2025-44883

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the tacIp parameter in the web_tacplus_serverEdit_post function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CVE-2025-44890CVE

CVE-2025-44890

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_notifyv3_add_post function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CVE-2025-4340CVE

CVE-2025-4340

A vulnerability classified as critical has been found in D-Link DIR-890L and DIR-806A1 up to 100CNb11/108B03. Affected is the function sub_175C8 of the file /htdocs/soap.cgi. The manipulation leads t…

CVSS 9.8EPSS 5.3%
Match for cwe-840
CVE-2025-44896CVE

CVE-2025-44896

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the bindEditMACName parameter in the web_acl_bindEdit_post function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CVE-2025-6328CVE

CVE-2025-6328

A vulnerability was found in D-Link DIR-815 1.01. It has been declared as critical. This vulnerability affects the function sub_403794 of the file hedwig.cgi. The manipulation leads to stack-based bu…

CVSS 8.8EPSS 1.2%
Match for cwe-840
CVE-2025-44891CVE

CVE-2025-44891

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the host_ip parameter in the web_snmp_v3host_add_post function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CVE-2025-44898CVE

CVE-2025-44898

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the theauthName parameter in the web_aaa_loginAuthlistEdit function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CVE-2025-41270CVE

CVE-2025-41270

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Console WebUI in Waterfall WF-500 TX and RX Hosts in versio…

CVSS 9.8EPSS 1.4%waterfall-security
Match for cwe-840
CVE-2025-44887CVE

CVE-2025-44887

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the radIpkey parameter in the web_radiusSrv_post function.

CVSS 9.8EPSS 0.5%
Match for cwe-840
CVE-2025-44893CVE

CVE-2025-44893

FW-WGS-804HPT v1.305b241111 was discovered to contain a stack overflow via the ruleNamekey parameter in the web_acl_mgmt_Rules_Apply_post function.

CVSS 9.8EPSS 0.7%
Match for cwe-840
CVE-2026-0840CVE

CVE-2026-0840

A security vulnerability has been detected in UTT 进取 520W 1.7.7-180627. Affected by this vulnerability is the function strcpy of the file /goform/formConfigNoticeConfig. The manipulation of the argum…

CVSS 8.8EPSS 4.1%
Match for cwe-840
CVE-2026-20086CVE

CVE-2026-20086

A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family could allow an una…

CVSS 8.6EPSS 0.4%
Match for cwe-840
CVE-2025-41281CVE

CVE-2025-41281

Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that al…

CVSS 7.8EPSS 0.5%waterfall-security
Match for cwe-840
CVE-2026-0784CVE

CVE-2026-0784

ALGO 8180 IP Audio Alerter Web UI Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ALGO 8180 IP…

CVSS 8.8EPSS 1.7%
Match for cwe-840
CVE-2025-15008CVE

CVE-2025-15008

A vulnerability was detected in Tenda WH450 1.0.0.18. This affects an unknown part of the file /goform/L7Port of the component HTTP Request Handler. Performing a manipulation of the argument page res…

CVSS 9.8EPSS 0.5%
Match for cwe-840
Hybrid search: an exact-match keyword pass (title + MITRE-ID + body-head) fused with Vertex AI semantic similarity (text-embedding-005, cosine vector search over the corpus) via reciprocal-rank fusion — exact IDs stay pinned, related concepts surface by meaning. Curated by Adam Lundqvist, Founder at SQUR.