-
YiFang CMS ≤ 2.0.5: SQL Identifier Injection in L_Admin_article::removeBackslashes() (Authenticated, Full Database Takeover)
-
Tenda W18E V2.0 httpd: Unauthenticated OS Command Injection in the Packet-Capture Diagnostic Feature (Root RCE)
-
Tenda CP3 V3.0 noodles Daemon: Unauthenticated File Download-and-Execute Backdoor on TCP/1300 (Root RCE)