Tuesday, September 29, 2026

7 Advisories Published – 9-29-26

Today CISA’s NCCIC-ICS published seven control system security advisories for products from Viidure, MikroTik, Anjvision, Baicells, VIVOTEK, TopTech, and Lantronix. 

Advisories  

Viidure Advisory - This advisory describes two vulnerabilities in the Viidure Dashcam Android Application. The vulnerabilities were reported to CISA by Bugrahan Karahan. CISA notes that: “Viidure did not respond to CISA's coordination attempts.” 

Mikrotik Advisory - This advisory describes an integer underflow vulnerability in the MikroTik RouterOS. The vulnerability was reported to CISA by an anonymous researcher.  

Anjvision Advisory -This advisory describes an initialization of resource with an insecure default vulnerability in the Anjvision YSSD-RTMP-H5 firmware. The vulnerabilities were reported to CISA by Andrew Lee. CISA notes that: “Anjvision has not responded to requests to work with CISA to mitigate these vulnerabilities.” 

Baicells Advisory - This advisory describes an uncaught exception vulnerability in the Baicells Technologies Nova 430H eNodeB. The vulnerability was reported to CISA by Qiqing Huang. CISA notes that: “Baicells has not responded to requests to work with CISA to mitigate this vulnerability.” 

VIVOTEK Advisory - This advisory describes a command injection vulnerability in the VIVOTEK Camera Firmware. The vulnerability was originally reported by Larry Cashdollar with proof-of-concept code. 

Toptech Advisory - This advisory describes 10 vulnerabilities in the Toptech Systems TMS7 and Tophat 7 terminal management systems. The vulnerabilities were reported by Sachin Shetty and Roy Duisters of Shell CyberDefence. 

Lantronix Advisory - This advisory describes two vulnerabilities in the Lantronix G520 Series Cellular Gateway. The vulnerabilities were reported to CISA by Ievgen Bondarenko. 

No comments:

 
/* Use this with templates/template-twocol.html */