CISA issues advisory on Tenda router command injection vulnerabilities
Tenda N300 and 4G03 Pro routers have command injection flaws enabling root access; no patches currently exist.
Decision Insights Threat Desk • November 27, 2025
Tenda N300 and 4G03 Pro routers have command injection flaws enabling root access; no patches currently exist.
Decision Insights Threat Desk • November 27, 2025
AVEVA found an XSS flaw in Application Server IDE up to 2023 R2 SP1 P02; updates to 2023 R2 SP1 P03 address the issue.
Decision Insights Threat Desk • November 27, 2025
A vulnerability classified under CVE-2025-10259 affects Mitsubishi Electric's MELSEC iQ-F Series, causing potential denial of service via improper validation in TCP communication. The issue impacts various versions worldwide, with mitigation advice including VPN use and restricted physical and network access.
Decision Insights Threat Desk • November 27, 2025
AVEVA Edge 2023 R2 and prior contain a cryptographic flaw allowing local attackers with file access to brute force passwords.
Decision Insights Threat Desk • November 27, 2025
A vulnerability in Opto 22's GRV-EPIC and groov RIO devices allows remote command execution with root privileges. Affected firmware versions are prior to 4.0.3. A patch is available, and CISA recommends network security measures.
Decision Insights Threat Desk • November 27, 2025
A vulnerability in Siemens TIA-Portal software used in Festo Didactic products allows potential arbitrary file creation or overwriting and code execution. Users are advised to update affected software versions and apply recommended cybersecurity practices to mitigate social engineering risks.