Daily briefing · June 28, 2026
Five Tenda Router Buffer Overflows Lead a Day of 47 New CVEs, All with Public Exploits
June 28, 2026 brought 47 newly published vulnerabilities, none rated critical and none yet flagged for active exploitation — but five high-severity stack-based buffer overflows in the Tenda JD12L router, all with public proof-of-concept code, demand immediate attention from network defenders. The day's remaining highlights include a dangerous use-after-free in the Zephyr RTOS DNS stack, multiple SQL injection flaws in a widely redistributed open-source academic scheduling system, and a path traversal vulnerability in the ruoyi-vue-pro enterprise framework.
Today’s brief
- Five Tenda JD12L router CVEs (CVSS 8.7) are all remotely exploitable with public PoC code — patch or isolate these devices now.
- Zephyr RTOS carries a use-after-free in its async DNS resolver that can corrupt memory in embedded/IoT devices.
- Three SQL injection flaws in SourceCodester's Class and Exam Timetabling System are publicly disclosed and remotely exploitable.
- A path traversal bug in ruoyi-vue-pro allows attackers to write files outside intended directories via the file upload endpoint.
0
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
A remotely exploitable stack-based buffer overflow in the Tenda JD12L's NatStaticSetting handler can be triggered by manipulating the 'page' argument. With a public exploit already available, attackers on the internet can attempt to gain control of affected routers without authentication.
2
The addressNat function of Tenda JD12L firmware 16.03.53.23 is vulnerable to a stack-based buffer overflow via the 'page' parameter, exploitable remotely with a public PoC. This mirrors CVE-2026-13519 in severity and attack surface, widening the risk on the same device.
3
Manipulation of the 'security_5g' argument in the Tenda JD12L's WifiBasicSet handler triggers a stack overflow, enabling potential remote code execution. The public disclosure of the exploit makes this an immediate risk for any exposed unit.
4
The WifiGuestSet function in Tenda JD12L is vulnerable to a stack overflow via the 'shareSpeed' parameter, with a publicly available exploit. Organizations using this device for guest network segmentation should treat it as untrusted until patched.
5
A stack-based buffer overflow in the PPTP server configuration function of Tenda JD12L can be triggered remotely via the 'startIp' parameter. The combination of remote exploitability and public PoC code makes this the fifth high-risk entry point on the same router model.
6
Zephyr's asynchronous DNS resolver passes a pointer to a stack-allocated state object as user data; if the semaphore wait times out before the resolver callback fires, the callback writes into freed stack memory, creating a use-after-free condition. Embedded and IoT systems running Zephyr with network connectivity should be evaluated for exposure, particularly in environments where DNS queries can be influenced externally.
7
A SQL injection vulnerability in the 'course_year_section' parameter of /preview6.php in SourceCodester Class and Exam Timetabling System 1.0 is remotely exploitable and publicly disclosed. Attackers can enumerate or exfiltrate the underlying database without special privileges.
8
The /preview.php endpoint of SourceCodester Class and Exam Timetabling System 1.0 is susceptible to the same SQL injection pattern via 'course_year_section', with a public exploit. Instances exposed to the internet should be taken offline or placed behind strict access controls immediately.
9
A path traversal flaw in the ruoyi-vue-pro framework's file upload endpoint allows remote attackers to write files outside the intended directory by manipulating the generated upload path. This can lead to webshell deployment or overwriting of sensitive configuration files on affected servers.
10
A third SQL injection entry point in SourceCodester Class and Exam Timetabling System 1.0 affects /preview4.php via the same 'course_year_section' parameter, with the exploit publicly available. The recurrence of this pattern across multiple endpoints suggests the vulnerability is systemic in this codebase.
Today’s recommendation: Prioritize firmware review and network isolation for all Tenda JD12L devices, and audit any internet-facing deployments of SourceCodester Class and Exam Timetabling System and ruoyi-vue-pro for the disclosed injection and traversal vectors. Where patches are unavailable, restrict administrative and web interfaces to trusted networks and enforce input validation at the perimeter.
Even on a day without active exploitation confirmed in the wild, the volume of public proof-of-concept code published today makes it essential to validate whether any of these affected components exist within your own attack surface before threat actors do it for you.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →Previous briefings
August 6, 2026 — 10 Active Exploits, 1 Weaponized in a Day: Critical Alert Across WordPress, SharePoint, SonicWall, and MoreAugust 5, 2026 — Cisco SD-WAN, MarkLogic, and PraisonAI Lead a Batch of Critical CVEs on a Calm Exploitation DayAugust 4, 2026 — Quiet Day Masks 10 Critical CVEs: RCE, Auth Bypass, and Stack Overflows in FocusAugust 3, 2026 — Adobe Campaign Classic and WAPT Server Hit by Multiple CVSS 10.0 VulnerabilitiesAugust 2, 2026 — Bouncy Castle Mass Patch Day: Six Critical CVEs Drop Alongside SQL Injection and Auth Bypass FlawsAugust 1, 2026 — WordPress Auth Bypasses and FreeRDP Heap Flaws Top a Calm Vulnerability DayJuly 31, 2026 — Calm Day Hides Critical Flaws: Hard-coded Keys, File Uploads, and Code Injection Dominate July 31July 30, 2026 — 32 Critical CVEs, No Active Exploitation: Azure Cosmos DB and IBM Products Lead a Heavy Patch DayJuly 29, 2026 — Cisco FMC Under Active Exploit, Joomla Gridbox Cluster Hits Critical Mass with Four CVEsJuly 28, 2026 — Quiet Day Hides Critical Vulnerabilities: IBM WebSphere, Apache Axis2, and Joomla Top the ListJuly 27, 2026 — CVE-2026-16812: VeloCloud Orchestrator Under Active Exploitation as Critical Flaws Pile Up Across Enterprise and WordPress StacksJuly 26, 2026 — Quiet Vulnerability Day as Brazil Faces Ransomware Wave From Multiple GroupsJuly 25, 2026 — CVSS 10.0 in SiYuan and Auth Bypass in OpenRemote Lead a Calm Day for New ExploitsJuly 24, 2026 — Three CVSS 10.0 Microsoft Cloud Flaws Lead a Calm but Notable Patch Dayview full archive →