Unpatched Calix flaw lets hackers bypass NAT to expose internal devices
Teaser from the source
An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. [...]
This is the RSS-feed teaser. Read the full article at the original source.
Read at BleepingComputer →More on Unpatched
Other advisories
- CVE-2025-59851lowHCL DFXAnalytics is affected by a Using Components with Known Vulnerabilities flaw where the application utilizes unpatched libraries or sub-components, whic…
- osv:CVE-2026-35667noneOpenClaw < 2026.3.24 - Improper Process Termination via Unpatched killProcessTree in shell-utils.ts
- osv:ECHO-ddb8-c818-edcanoneVulnerable code is not present in libraw 0.21.4 (the version shipped in Debian trixie). The CVE describes a heap out-of-bounds write in HuffTable::initval (src/decompressors/losslessjpeg.cpp), reachable via LibRaw::sony_ycbcr_load_raw -> LibRaw_LjpegDecompressor::initialize -> HuffTable::initval. None of those symbols exist in 0.21.4: the src/decompressors/ directory, the LibRaw_LjpegDecompressor class, and the sony_ycbcr_load_raw entry point were all introduced together in libraw 0.22.0. Empirically confirmed by running the public PoC from https://github.com/biniamf/pocs/tree/main/libraw_lljpeg against an ASan build of unpatched libraw 0.21.4: the file is rejected at open with "Unsupported file format or not RAW file"; the same PoC reproduces the heap-buffer-overflow in 0.22.0 with the stack trace from the Talos report.
- CVE-2024-52798nonepath-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x
- osv:CVE-2024-52798nonepath-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x
- CVE-2024-44625noneUnpatched Remote Code Execution in Gogs in gogs.io/gogs
- CVE-2023-30549noneUnpatched extfs vulnerabilities are exploitable through suid-mode Apptainer in github.com/apptainer/apptainer
- CVE-2023-30549noneUnpatched extfs vulnerabilities are exploitable through suid-mode Apptainer
Other news entries
- Newsbleepingcomputer2026-10-09Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto
- Newssecurityweek2026-10-09Unpatched AhsayCBS Vulnerabilities Exploited in the Wild
- Newsthehackernews2026-10-07Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
- Newsthehackernews2026-10-01Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
- Newsthehackernews2026-09-27Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
- Newsbleepingcomputer2026-09-25ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
- Newsthehackernews2026-09-24Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
- Newsthehackernews2026-09-23Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
ID