Showing posts with label ThingsBoard. Show all posts
Showing posts with label ThingsBoard. Show all posts

Sunday, June 21, 2026

Review - Public ICS Disclosures – Week of 6-13-26 – Part 2

For Part 2 we have 11 additional vendor disclosures from Ingecon, Moxa (3), NI, Splunk (2), ThingsBoard, TP-Link, Turck, and Zyxel. Part 3 is coming tomorrow. 

Advisories  

Ingecon Advisory - INCIBE-CERT published an advisory that describes a use of broken or risky cryptographic algorithm vulnerability in the Ingecon EMS Board. 

Moxa Advisory #1 - Moxa published an advisory that describes a missing authentication vulnerability in their Serial Device Servers. 

Moxa Advisory #2 - Moxa published an advisory that describes two vulnerabilities in their Serial Device Servers. The vulnerabilities were reported by Remi ONNO of CS GROUP. 

Moxa Advisory #3 - Moxa published an advisory that describes an improper validation of specified type of input vulnerability in their Serial Device Servers. 

NI Advisory - NI published an advisory that describes seven vulnerabilities in their gRPC Device Server. 

Splunk Advisory #1 - Splunk published an advisory that describes an OS command injection vulnerability in their AI Toolkit. 

Splunk Advisory #2 - Splunk published an advisory that describes an OS command injection vulnerability in their AI Toolkit. 

ThingsBoard Advisory - JP-CERT published an advisory that describes a prototype pollution vulnerability in the ThingsBoard open-source IoT platform. 

TP-Link Advisory - TP-Link published an advisory that describes two OS command injection vulnerabilities in their TL-WR940N wireless router. 

Turck Advisory - CERT-VDE published an advisory that discusses two vulnerabilities (one with a publicly available exploit) in Turck Managed Ethernet Switches. 

Zyxel Advisory - Zyxel published an advisory that describes a stack-based buffer overflow vulnerability in their GS1900 series switches. 


For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-6-c60 - subscription required. 

Sunday, May 10, 2026

Review - Public ICS Disclosures – Week of 5-2-26 – Part 2

 For Part 2 we have seven additional vendor disclosures from WatchGuard (4) and VEGA (3). There are eight researcher reports of vulnerabilities in products from TP-Link. Finally, we have two exploits for products from PX4 and ThingsBoard. 

Advisories  

WatchGuard Advisory #1 - WatchGuard published an advisory that describes two vulnerabilities in their WatchGuard Agent on Windows product.  

WatchGuard Advisory #2 - WatchGuard published an advisory that describes an incorrect permission assignment for critical resource vulnerability in their WatchGuard Agent on Windows product. 

WatchGuard Advisory #3 - WatchGuard published an advisory that describes a stack-based buffer overflow vulnerability in their WatchGuard Agent Discovery Service on Windows product. 

WatchGuard Advisory #4 - WatchGuard published an advisory that describes a stack-based buffer overflow vulnerability in their WatchGuard Agent Discovery Service on Windows product. 

VEGA Advisory #1 - CERT-VDE published an advisory that describes a missing authentication for critical function vulnerability in the VEGAPULS two- and four-wire products. 

VEGA Advisory #2 - CERT-VDE published an advisory that describes a missing authentication for critical function vulnerability in the VEGAPULS Air products. 

VEGA Advisory #3 - CERT-VDE published an advisory that describes a missing authentication for critical function vulnerability in the VEGAPULS Bluetooth products. 

Researcher Reports  

TP-Link Reports - Cisco Talos published eight reports describing vulnerabilities in the TP-Link Archer AX53 AX3000 Dual Band Gigabit Wi-Fi 6 Router. 

Exploits  

PX4 Exploit Mohammed Idrees Banyamer published an exploit for a stack-based buffer overflow vulnerability in the PX4Autopilot flight controller. 

ThingsBoard Exploit Tamil Mathi T published an exploit for a Server-side request forgery vulnerability in the ThingsBoard IoT Platform. 


For more information on these disclosures, see my article at CFSN Detailed Analysis - https://patrickcoyle.substack.com/p/public-ics-disclosures-week-of-5-338 - subscription required. 

 
/* Use this with templates/template-twocol.html */