NVD disclosure day

Published threat advisories for August 28, 2022

CVE advisoryCRITICAL

CVE-2022-38555

Linksys E1200 Buffer Overflow Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical buffer overflow vulnerability in Linksys E1200 firmware could allow an attacker to execute code or disrupt services if the device's web management interface is reachable. Confirmation of device relevance and exposure is needed to understand the potential impact.

CVE advisoryKnown Exploit

CVE-2022-37055

D-Link Router Buffer Overflow Vulnerability.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

D-Link routers contain a buffer overflow vulnerability, enabling unauthorized control. This affects network operations and data integrity. The risk to organizations includes potential system compromise and data breaches due to the ease of remote exploitation.

• CISA KEV

CVE advisoryCRITICAL

CVE-2022-37053

TRENDnet TEW733GR Command Injection Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical command injection vulnerability exists in TRENDnet routers, allowing unauthenticated attackers to execute arbitrary commands remotely. This could compromise device operation and expose network traffic. Confirmation of affected device presence and exposure is essential for risk assessment and remediation plan