|
311
|
- |
|
-
|
-
|
The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.
New
|
CWE-287
Improper Authentication
|
CVE-2026-49194
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312
|
- |
|
-
|
-
|
Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft.
New
|
CWE-287
Improper Authentication
|
CVE-2026-49202
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313
|
- |
|
-
|
-
|
Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.
New
|
CWE-287
Improper Authentication
|
CVE-2026-49203
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314
|
- |
|
-
|
-
|
Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation.
New
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-49204
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315
|
- |
|
-
|
-
|
System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data.
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-50205
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
316
|
- |
|
-
|
-
|
Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files.
New
|
CWE-78
OS Command
|
CVE-2026-50206
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
317
|
- |
|
-
|
-
|
The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellular connectivity.
New
|
CWE-22
Path Traversal
|
CVE-2026-50207
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
318
|
- |
|
-
|
-
|
High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic.
New
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2026-50208
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319
|
- |
|
-
|
-
|
Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker.
New
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-50209
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320
|
- |
|
-
|
-
|
The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption.
New
|
CWE-200
Information Exposure
|
CVE-2026-50210
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|