Daily briefing · June 28, 2026
Five Tenda Router Buffer Overflows Lead a Day of 47 New CVEs, All with Public Exploits
June 28, 2026 brought 47 newly published vulnerabilities, none rated critical and none yet flagged for active exploitation — but five high-severity stack-based buffer overflows in the Tenda JD12L router, all with public proof-of-concept code, demand immediate attention from network defenders. The day's remaining highlights include a dangerous use-after-free in the Zephyr RTOS DNS stack, multiple SQL injection flaws in a widely redistributed open-source academic scheduling system, and a path traversal vulnerability in the ruoyi-vue-pro enterprise framework.
Today’s brief
- Five Tenda JD12L router CVEs (CVSS 8.7) are all remotely exploitable with public PoC code — patch or isolate these devices now.
- Zephyr RTOS carries a use-after-free in its async DNS resolver that can corrupt memory in embedded/IoT devices.
- Three SQL injection flaws in SourceCodester's Class and Exam Timetabling System are publicly disclosed and remotely exploitable.
- A path traversal bug in ruoyi-vue-pro allows attackers to write files outside intended directories via the file upload endpoint.
0
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
A remotely exploitable stack-based buffer overflow in the Tenda JD12L's NatStaticSetting handler can be triggered by manipulating the 'page' argument. With a public exploit already available, attackers on the internet can attempt to gain control of affected routers without authentication.
2
The addressNat function of Tenda JD12L firmware 16.03.53.23 is vulnerable to a stack-based buffer overflow via the 'page' parameter, exploitable remotely with a public PoC. This mirrors CVE-2026-13519 in severity and attack surface, widening the risk on the same device.
3
Manipulation of the 'security_5g' argument in the Tenda JD12L's WifiBasicSet handler triggers a stack overflow, enabling potential remote code execution. The public disclosure of the exploit makes this an immediate risk for any exposed unit.
4
The WifiGuestSet function in Tenda JD12L is vulnerable to a stack overflow via the 'shareSpeed' parameter, with a publicly available exploit. Organizations using this device for guest network segmentation should treat it as untrusted until patched.
5
A stack-based buffer overflow in the PPTP server configuration function of Tenda JD12L can be triggered remotely via the 'startIp' parameter. The combination of remote exploitability and public PoC code makes this the fifth high-risk entry point on the same router model.
6
Zephyr's asynchronous DNS resolver passes a pointer to a stack-allocated state object as user data; if the semaphore wait times out before the resolver callback fires, the callback writes into freed stack memory, creating a use-after-free condition. Embedded and IoT systems running Zephyr with network connectivity should be evaluated for exposure, particularly in environments where DNS queries can be influenced externally.
7
A SQL injection vulnerability in the 'course_year_section' parameter of /preview6.php in SourceCodester Class and Exam Timetabling System 1.0 is remotely exploitable and publicly disclosed. Attackers can enumerate or exfiltrate the underlying database without special privileges.
8
The /preview.php endpoint of SourceCodester Class and Exam Timetabling System 1.0 is susceptible to the same SQL injection pattern via 'course_year_section', with a public exploit. Instances exposed to the internet should be taken offline or placed behind strict access controls immediately.
9
A path traversal flaw in the ruoyi-vue-pro framework's file upload endpoint allows remote attackers to write files outside the intended directory by manipulating the generated upload path. This can lead to webshell deployment or overwriting of sensitive configuration files on affected servers.
10
A third SQL injection entry point in SourceCodester Class and Exam Timetabling System 1.0 affects /preview4.php via the same 'course_year_section' parameter, with the exploit publicly available. The recurrence of this pattern across multiple endpoints suggests the vulnerability is systemic in this codebase.
Today’s recommendation: Prioritize firmware review and network isolation for all Tenda JD12L devices, and audit any internet-facing deployments of SourceCodester Class and Exam Timetabling System and ruoyi-vue-pro for the disclosed injection and traversal vectors. Where patches are unavailable, restrict administrative and web interfaces to trusted networks and enforce input validation at the perimeter.
Even on a day without active exploitation confirmed in the wild, the volume of public proof-of-concept code published today makes it essential to validate whether any of these affected components exist within your own attack surface before threat actors do it for you.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →Previous briefings
September 20, 2026 — Dozens of Critical PoC Flaws Surface in Routers and Research Tools, But No Active Exploitation DetectedSeptember 19, 2026 — Calm Vulnerability Day Masks Serious Flaws in Routers, WordPress, and SuricataSeptember 18, 2026 — WordPress, IBM, and vm2 Flaws Anchor a High-Alert Day With 5 CVEs Already Under Active ExploitationSeptember 17, 2026 — Six CVSS 10.0 Azure Flaws Lead a Heavy Patch Day as Acronis Backup Plugin Faces Active ExploitationSeptember 16, 2026 — Cisco Infrastructure Flooded With CVSS 10 Flaws as VulnCheck Spots Active Exploitation Before CISASeptember 15, 2026 — Oracle Patch Tuesday Surge and Yonyou Active Exploitation Drive ATTENTION-Level AlertSeptember 14, 2026 — Cisco Secure Email Under Active Exploitation as 58 Critical CVEs SurfaceSeptember 13, 2026 — WordPress Plugin Flaw Leads Quiet Day With 8 Critical CVEs and No Active ExploitationSeptember 12, 2026 — WordPress Plugin Blitz: Nine Critical RCE and Takeover Flaws Disclosed on a Quiet Exploit DaySeptember 11, 2026 — GitLab Critical Zero-Day Under Active Exploitation Leads a Heavy Patch Day with 36 Critical CVEsSeptember 10, 2026 — Ten Critical CVEs Published on a Calm Threat Day as Brazil Faces Ransomware SurgeSeptember 9, 2026 — Three CVEs Already Exploited Before CISA Confirmation, Dual Check Point RCE and cPanel SQLi-to-Root Round Out a High-Alert DaySeptember 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on Brazilview full archive →