Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-134'

View all threats tagged with 'cwe-134'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-134

Threats Tagged 'cwe-134'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-57877: CWE-134 Use of Externally-Controlled format string in GeoVision Inc. GV-LPCLPC2011/2211CVE-2026-57877
0

An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper handling of externally controlled input during log message formatting in the login processing path. A remote attacker may exploit this vulnerability by sending crafted login data, potentially causing information disclosure, memory corruption, or a denial of service.

Join the discussion
CVE-2026-10828: CWE-134: Use of Externally-Controlled Format String in Moxa NPort W2150A-W4/W2250A-W4 SeriesCVE-2026-10828
0

A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior. This vulnerability stems from insufficient input validation and improper handling of externally supplied format strings. An attacker could exploit this vulnerability by sending crafted input to the web service, causing unintended memory disclosure. Successful exploitation may allow an attacker to leak sensitive memory contents and determine critical memory addresses, potentially bypassing Address Space Layout Randomization (ASLR) protections.

Join the discussion
CVE-2026-6250: CWE-134 Use of Externally-Controlled format string in TP-Link Systems Inc. Tapo C110 v2CVE-2026-6250
0

CVE-2026-6250 is a format string vulnerability in the ONVIF service of TP-Link Tapo C110 v2. It allows an authenticated attacker to manipulate stack memory by supplying user-controlled input as a format string. Exploitation can lead to unauthorized factory reset, causing loss of configuration, deletion of stored credentials, and service disruption.

Join the discussion
CVE-2026-6242: CWE-134 Use of Externally-Controlled format string in TP-Link Systems Inc. Tapo C520WS v2CVE-2026-6242
0

An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper handling of externally supplied parameters within formatting functions. An attacker may inject crafted format strings into event subscription requests or notification generation path to disrupt normal service execution. Successful exploitation may cause the event notification service to terminate unexpectedly, resulting in the loss of real-time alarm functionality and disruption of event notifications.

Join the discussion
CVE-2026-6241: CWE-134 Use of Externally-Controlled format string in TP-Link Systems Inc. Tapo C520WS v2CVE-2026-6241
0

An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly passed to formatting functions without adequate sanitization. An attacker can inject format specifiers into ONVIF scope parameters to manipulate memory handling behavior. Successful exploitation may cause the ONVIF management service to crash, resulting in DoS condition that impacts normal device operation.

Join the discussion
CVE-2026-50211: CWE-134: Use of Externally-Controlled Format String in Acer Connect M6E 5G Portable WiFi RouterCVE-2026-50211
0

Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Tag: cwe-134
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses