Showing posts with label D-Link. Show all posts
Showing posts with label D-Link. Show all posts

Monday, June 22, 2026

Review - Public ICS Disclosures – Week of 6-13-26 – Part 3

For Part 3 we have 10 vendor updates from CODESYS (4), D-Link (2), FortiGuard, HP, Moxa (2). There are two researcher reports for vulnerabilities in products from Phoenix Contact and Sprecher Automation. Finally, we have two exploits for products from D-Link and Genetec. 

Updates  

CODESYS Update #1 - CODESYS published an update for their Auditlog advisory that was originally published on March 24th, 2026. 

CODESYS Update #2 - CODESYS published an update for their Control advisory that was originally published on May 21st, 2026, and most recently updated on May 26th, 2026. 

CODESYS Update #3 - CODESYS published an update for their Control advisory that was originally published on May 21st, 2026, and most recently updated on May 26th, 2026. 

CODESYS Updte #4 - CODESYS published an update for their Control V3 advisory that was originally puublished on March 24th, 2026. 

D-Link Advisory #1 - D-Link published an update for their DWR-921 advisory that was originally published on April 22nd, 2021.  

D-Link Advisory #2 - D-Link published an update for their DCS-935L advisory that was originally published on September 12th, 2025. 

FortiGuard Update - FortiGuard published an update for their FortiOS advisory that was originally published on June 10th, 2025. 

HP Update - HP published an update for their Intel Chipset advisory that was originally published on October 17th, 2025, and most recently updated on March 19th, 2026. 

Moxa Update #1 - Moxa published an update for their Linux Kernel advisory that was originally published on May 26th, 2026. 

Moxa Update #2 - Moxa published an update for their NPort 5000 Series advisory that was originally published on October 3rd, 2023, and most recently updated on October 23rd, 2023. 

Researcher Reports  

Phoenix Contact Report - Nozomi Networks published a report that describes six vulnerabilities in the Phoenix Contact PLCnext product. 

Sprecher Report - SEC Consult published a report that describes seven vulnerabilities in the Sprecher SPRECON-E-C/-E-P/-E-T3 systems. 

Exploits  

D-Link Exploit - Indoushka published an exploit for a privlege escalation vulnerability in the D-Link DSL2600U routers. 

Genetec Exploit - Indoushka published an exploit for for an incorrect permission assignement for criitical resource vulnerability in the Genetec RabbitMQ. 


For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-ce6 - subscription required. 

Saturday, June 6, 2026

Review – Public ICS Disclosures – Week of May 30th, 2026 – Part 1

This week we have a moderately busy disclosure week. For Part 1 there are 12 vendor disclosures from Arista, Dassault Sytems (2), D-Link, Eaton, HP, HPE (2), MBS, NI, Phillips, and Phoenix Contact. 

Advisories  

Arista Advisory Arista published an advisory that discusses an improper restriction of operations within the bounds of a memory buffer vulnerability (with publicly available exploit) in their EOS platform products. 

Dassault Advisory #1 - Dassault published an advisory that describes a cross-site scripting vulnerabbility in their Process Experience Studio in DELMIA Service Process Engineer. 

Dassault Advisory #2 - Dassault published an advisory that describes a deserialization of untrusted data vulnerability in their Teamwork Cloud from No Magic product. 

D-Link Advisory D-Link published an advisory that describes a use of weak credentials vulnerability in their DWR-X1820 router. 

Eaton Advisory - Eaton published an advisory that discusses a TOCTOU race condition vulnerabiltiy in their ProView NXG application software. 

HP Advisory - HP published an advisory that describes a stack-based buffer overflow vulnerability (with publicly available exploit) in their Poly Voice products. 

HPE Advisory #1 HPE published an advisory that discusses ten vulnerabilities (four with publicly available exploits) in their Telco Network Function Virtualization Orchestrator. 

HPE Advisory #2 - HPE published an advisory that discusses a TOCTOU race condition vulnerability in their ArubaOS-CX Switches. 

MBS Advisory - CERT-VDE published an advisory that describes 11 vulnerabilities in the MBS Universal Gateways (UGW-A-Series, UGW-X-Series) used in multiple MBS products.3 

NI Advisory NI published an advisory that describes two vulnerabilities in their NI-PAL product. 

Philips Advisory - Philips published an advisory that discusses the Windows’ BlueHammer, RedSun, and UnDefend vulnerabilities. 

Phoenix Contact Advisory Phoenix Contact published an advisory that describs an exposure of sensitive information to an unauthorized actor vulnerability in their CHARX SEC-3150 product. 


For more information on these disclosures, including links to 3rd party advisories, researcher reports, and exploits, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-may - subscription required. 

 
/* Use this with templates/template-twocol.html */