|
1031
|
- |
|
-
|
-
|
The hard-coded APK resource files never expire, and the shared scepter leads to information leaks and potential misuse.
New
|
CWE-200
Information Exposure
|
CVE-2026-49187
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1032
|
- |
|
-
|
-
|
The ai_cmd utility executes with full root permissions. It pipes socket inputs directly to popen(), paving the way for unauthenticated users to execute arbitrary root commands.
New
|
CWE-489
Exposure of Data Element to Wrong Session
|
CVE-2026-49188
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1033
|
- |
|
-
|
-
|
Unchecked public access permissions on a core Broadcast Receiver allow unauthorized local software components to invoke administrative operations.
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-49189
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1034
|
- |
|
-
|
-
|
The system fails to evaluate instructional permissions over multiple internal operation codes (opcodes), permitting unauthorized application installations or command executions.
New
|
CWE-78
OS Command
|
CVE-2026-49190
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1035
|
- |
|
-
|
-
|
The production build of the M3WebServer hard-codes its backend API keys, which can be easily intercepted through verbose error handling pages.
New
|
CWE-287
Improper Authentication
|
CVE-2026-49191
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1036
|
- |
|
-
|
-
|
The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping.
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-49192
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1037
|
- |
|
-
|
-
|
Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet.
New
|
CWE-200
Information Exposure
|
CVE-2026-49193
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1038
|
- |
|
-
|
-
|
The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.
New
|
CWE-287
Improper Authentication
|
CVE-2026-49194
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1039
|
- |
|
-
|
-
|
Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft.
New
|
CWE-287
Improper Authentication
|
CVE-2026-49202
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1040
|
- |
|
-
|
-
|
Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted.
New
|
CWE-287
Improper Authentication
|
CVE-2026-49203
|
2026-06-5 00:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|