Daily briefing · June 28, 2026

Five Tenda Router Buffer Overflows Lead a Day of 47 New CVEs, All with Public Exploits

Automated Vexday summary · sources: NVD, CISA KEV, EPSS

June 28, 2026 brought 47 newly published vulnerabilities, none rated critical and none yet flagged for active exploitation — but five high-severity stack-based buffer overflows in the Tenda JD12L router, all with public proof-of-concept code, demand immediate attention from network defenders. The day's remaining highlights include a dangerous use-after-free in the Zephyr RTOS DNS stack, multiple SQL injection flaws in a widely redistributed open-source academic scheduling system, and a path traversal vulnerability in the ruoyi-vue-pro enterprise framework.

Today’s brief
  • Five Tenda JD12L router CVEs (CVSS 8.7) are all remotely exploitable with public PoC code — patch or isolate these devices now.
  • Zephyr RTOS carries a use-after-free in its async DNS resolver that can corrupt memory in embedded/IoT devices.
  • Three SQL injection flaws in SourceCodester's Class and Exam Timetabling System are publicly disclosed and remotely exploitable.
  • A path traversal bug in ruoyi-vue-pro allows attackers to write files outside intended directories via the file upload endpoint.
0
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-13519HIGH 8.7PoCaffects JD12L
A remotely exploitable stack-based buffer overflow in the Tenda JD12L's NatStaticSetting handler can be triggered by manipulating the 'page' argument. With a public exploit already available, attackers on the internet can attempt to gain control of affected routers without authentication.
2
CVE-2026-13518HIGH 8.7PoCaffects JD12L
The addressNat function of Tenda JD12L firmware 16.03.53.23 is vulnerable to a stack-based buffer overflow via the 'page' parameter, exploitable remotely with a public PoC. This mirrors CVE-2026-13519 in severity and attack surface, widening the risk on the same device.
3
CVE-2026-13517HIGH 8.7PoCaffects JD12L
Manipulation of the 'security_5g' argument in the Tenda JD12L's WifiBasicSet handler triggers a stack overflow, enabling potential remote code execution. The public disclosure of the exploit makes this an immediate risk for any exposed unit.
4
CVE-2026-13516HIGH 8.7PoCaffects JD12L
The WifiGuestSet function in Tenda JD12L is vulnerable to a stack overflow via the 'shareSpeed' parameter, with a publicly available exploit. Organizations using this device for guest network segmentation should treat it as untrusted until patched.
5
CVE-2026-13515HIGH 8.7PoCaffects JD12L
A stack-based buffer overflow in the PPTP server configuration function of Tenda JD12L can be triggered remotely via the 'startIp' parameter. The combination of remote exploitability and public PoC code makes this the fifth high-risk entry point on the same router model.
6
CVE-2026-10646HIGH 7.4affects zephyr
Zephyr's asynchronous DNS resolver passes a pointer to a stack-allocated state object as user data; if the semaphore wait times out before the resolver callback fires, the callback writes into freed stack memory, creating a use-after-free condition. Embedded and IoT systems running Zephyr with network connectivity should be evaluated for exposure, particularly in environments where DNS queries can be influenced externally.
7
CVE-2026-13486MEDIUM 6.9PoCaffects Class and Exam Timetabling System
A SQL injection vulnerability in the 'course_year_section' parameter of /preview6.php in SourceCodester Class and Exam Timetabling System 1.0 is remotely exploitable and publicly disclosed. Attackers can enumerate or exfiltrate the underlying database without special privileges.
8
CVE-2026-13485MEDIUM 6.9PoCaffects Class and Exam Timetabling System
The /preview.php endpoint of SourceCodester Class and Exam Timetabling System 1.0 is susceptible to the same SQL injection pattern via 'course_year_section', with a public exploit. Instances exposed to the internet should be taken offline or placed behind strict access controls immediately.
9
CVE-2026-13528MEDIUM 6.9affects ruoyi-vue-pro
A path traversal flaw in the ruoyi-vue-pro framework's file upload endpoint allows remote attackers to write files outside the intended directory by manipulating the generated upload path. This can lead to webshell deployment or overwriting of sensitive configuration files on affected servers.
10
CVE-2026-13527MEDIUM 6.9affects Class and Exam Timetabling System
A third SQL injection entry point in SourceCodester Class and Exam Timetabling System 1.0 affects /preview4.php via the same 'course_year_section' parameter, with the exploit publicly available. The recurrence of this pattern across multiple endpoints suggests the vulnerability is systemic in this codebase.
Today’s recommendation: Prioritize firmware review and network isolation for all Tenda JD12L devices, and audit any internet-facing deployments of SourceCodester Class and Exam Timetabling System and ruoyi-vue-pro for the disclosed injection and traversal vectors. Where patches are unavailable, restrict administrative and web interfaces to trusted networks and enforce input validation at the perimeter.
Even on a day without active exploitation confirmed in the wild, the volume of public proof-of-concept code published today makes it essential to validate whether any of these affected components exist within your own attack surface before threat actors do it for you.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →
Previous briefings
August 6, 202610 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 202632 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →