Threats Tagged 'cwe-134'
View all threats tagged with 'cwe-134'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-134'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-57877: CWE-134 Use of Externally-Controlled format string in GeoVision Inc. GV-LPCLPC2011/2211CVE-2026-57877 0 An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper handling of externally controlled input during log message formatting in the login processing path. A remote attacker may exploit this vulnerability by sending crafted login data, potentially causing information disclosure, memory corruption, or a denial of service. Join the discussion | CVE Database V5 | 06/26/2026, 07:17:24 UTC Added: 06/26/2026, 07:46:06 UTC |
CVE-2026-10828: CWE-134: Use of Externally-Controlled Format String in Moxa NPort W2150A-W4/W2250A-W4 SeriesCVE-2026-10828 0 A format string vulnerability has been found in the "alias" parameter of the Serial Param configuration page in the NPort W2150A-W4/W2250A-W4 Series version 1.5 and prior. This vulnerability stems from insufficient input validation and improper handling of externally supplied format strings. An attacker could exploit this vulnerability by sending crafted input to the web service, causing unintended memory disclosure. Successful exploitation may allow an attacker to leak sensitive memory contents and determine critical memory addresses, potentially bypassing Address Space Layout Randomization (ASLR) protections. Join the discussion | CVE Database V5 | 06/16/2026, 10:16:12 UTC Added: 06/16/2026, 11:30:18 UTC |
CVE-2026-6250: CWE-134 Use of Externally-Controlled format string in TP-Link Systems Inc. Tapo C110 v2CVE-2026-6250 0 CVE-2026-6250 is a format string vulnerability in the ONVIF service of TP-Link Tapo C110 v2. It allows an authenticated attacker to manipulate stack memory by supplying user-controlled input as a format string. Exploitation can lead to unauthorized factory reset, causing loss of configuration, deletion of stored credentials, and service disruption. Join the discussion | CVE Database V5 | 06/11/2026, 20:46:09 UTC Added: 06/11/2026, 21:31:04 UTC |
CVE-2026-6242: CWE-134 Use of Externally-Controlled format string in TP-Link Systems Inc. Tapo C520WS v2CVE-2026-6242 0 An authenticated format string vulnerability exists in the ONVIF Subscribe service in Tapo C520WS v2 due to improper handling of externally supplied parameters within formatting functions. An attacker may inject crafted format strings into event subscription requests or notification generation path to disrupt normal service execution. Successful exploitation may cause the event notification service to terminate unexpectedly, resulting in the loss of real-time alarm functionality and disruption of event notifications. Join the discussion | CVE Database V5 | 06/05/2026, 23:52:36 UTC Added: 06/06/2026, 00:18:35 UTC |
CVE-2026-6241: CWE-134 Use of Externally-Controlled format string in TP-Link Systems Inc. Tapo C520WS v2CVE-2026-6241 0 An authenticated format string vulnerability is present in the ONVIF AddScopes in Tapo C520WS v2, where user-controlled input is improperly passed to formatting functions without adequate sanitization. An attacker can inject format specifiers into ONVIF scope parameters to manipulate memory handling behavior. Successful exploitation may cause the ONVIF management service to crash, resulting in DoS condition that impacts normal device operation. Join the discussion | CVE Database V5 | 06/05/2026, 23:52:18 UTC Added: 06/06/2026, 00:18:35 UTC |
CVE-2026-50211: CWE-134: Use of Externally-Controlled Format String in Acer Connect M6E 5G Portable WiFi RouterCVE-2026-50211 0 Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers. Join the discussion | CVE Database V5 | 06/04/2026, 07:28:12 UTC Added: 06/04/2026, 08:48:47 UTC |
Showing 1 to 6 of 6 results