View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Knot Resolver before 6.4.1 vulnerable to remote code execution

🕵️ RESEARCH & DEEP DIVES

  • Knot Resolver before 6.4.1 vulnerable to remote code execution via heap buffer overflow — cve.threatint.com
    Knot Resolver versions before 6.4.1 are vulnerable to remote code execution via a heap buffer overflow.

    • Applies to Knot Resolver versions before 6.4.1
    • Vulnerability is a heap-based buffer overflow in the DNS-over-QUIC (DoQ) receive path
    • Allows remote code execution without user interaction or privileges
    • CVSS 3.1 score 8.1 with network attack vector and high impact on integrity
  • Redis before 8.8.0 vulnerable to RCE via RESTORE command due to double free bug — cve.threatint.com
    Redis versions before 8.8.0 allow remote code execution via a RESTORE command exploit.

    • Applies to Redis versions before 8.8.0
    • Vulnerability in RESTORE command when an authenticated attacker executes it
    • Double free occurs when the same NACK is referenced by multiple consumers and deleted via XGROUP DELCONSUMER
    • Exploit leads to remote code execution due to incomplete fix of CVE-2026-25243
    • Requires authentication and high complexity (CVSS 7.5, AV:N/AC:H/PR:L/UI:N)

🔓 CVEs & KEV

  • CVE-2026-61884 — CVSS 9.8 — Tycon Systems TPDIN-Monitor-WEB2 Authentication Bypass Using an Alternate Path
  • CVE-2026-60134 — CVSS 8.8 — Weintek cMT3092X Reliance on Cookies without Validation and Integrity Checking
  • CVE-2026-61892 — CVSS 8.8 — Weintek cMT3092X Incorrect Permission Assignment for Critical Resource
  • CVE-2026-66337 — CVSS 6.5 — Libsoup: heap buffer over-read via integer underflow in soup_filter
  • CVE-2026-66339 — CVSS 6.5 — Libsoup: proxy credentials leak to destination server via proxy-auth header
  • CVE-2026-61886 — CVSS 6.5 — Weintek cMT3092X Plaintext Storage of a Password
  • CVE-2026-60135 — CVSS 6.5 — Weintek cMT3092X Incorrect User Management
  • CVE-2026-66338 — CVSS 5.4 — Libsoup: http request smuggling via permissive chunk-size parsing
  • CVE-2026-55985 — CVSS 4.3 — Tycon Systems TPDIN-Monitor-WEB2 Cleartext Storage of Sensitive Information
  • CVE-2026-16280 — CVSS — GPU DDK - Integer overflow in _PMRLogicalOffsetToPhysicalOffset function

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check