Daily briefing · June 28, 2026
Five Tenda Router Buffer Overflows Lead a Day of 47 New CVEs, All with Public Exploits
June 28, 2026 brought 47 newly published vulnerabilities, none rated critical and none yet flagged for active exploitation — but five high-severity stack-based buffer overflows in the Tenda JD12L router, all with public proof-of-concept code, demand immediate attention from network defenders. The day's remaining highlights include a dangerous use-after-free in the Zephyr RTOS DNS stack, multiple SQL injection flaws in a widely redistributed open-source academic scheduling system, and a path traversal vulnerability in the ruoyi-vue-pro enterprise framework.
Today’s brief
- Five Tenda JD12L router CVEs (CVSS 8.7) are all remotely exploitable with public PoC code — patch or isolate these devices now.
- Zephyr RTOS carries a use-after-free in its async DNS resolver that can corrupt memory in embedded/IoT devices.
- Three SQL injection flaws in SourceCodester's Class and Exam Timetabling System are publicly disclosed and remotely exploitable.
- A path traversal bug in ruoyi-vue-pro allows attackers to write files outside intended directories via the file upload endpoint.
0
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
A remotely exploitable stack-based buffer overflow in the Tenda JD12L's NatStaticSetting handler can be triggered by manipulating the 'page' argument. With a public exploit already available, attackers on the internet can attempt to gain control of affected routers without authentication.
2
The addressNat function of Tenda JD12L firmware 16.03.53.23 is vulnerable to a stack-based buffer overflow via the 'page' parameter, exploitable remotely with a public PoC. This mirrors CVE-2026-13519 in severity and attack surface, widening the risk on the same device.
3
Manipulation of the 'security_5g' argument in the Tenda JD12L's WifiBasicSet handler triggers a stack overflow, enabling potential remote code execution. The public disclosure of the exploit makes this an immediate risk for any exposed unit.
4
The WifiGuestSet function in Tenda JD12L is vulnerable to a stack overflow via the 'shareSpeed' parameter, with a publicly available exploit. Organizations using this device for guest network segmentation should treat it as untrusted until patched.
5
A stack-based buffer overflow in the PPTP server configuration function of Tenda JD12L can be triggered remotely via the 'startIp' parameter. The combination of remote exploitability and public PoC code makes this the fifth high-risk entry point on the same router model.
6
Zephyr's asynchronous DNS resolver passes a pointer to a stack-allocated state object as user data; if the semaphore wait times out before the resolver callback fires, the callback writes into freed stack memory, creating a use-after-free condition. Embedded and IoT systems running Zephyr with network connectivity should be evaluated for exposure, particularly in environments where DNS queries can be influenced externally.
7
A SQL injection vulnerability in the 'course_year_section' parameter of /preview6.php in SourceCodester Class and Exam Timetabling System 1.0 is remotely exploitable and publicly disclosed. Attackers can enumerate or exfiltrate the underlying database without special privileges.
8
The /preview.php endpoint of SourceCodester Class and Exam Timetabling System 1.0 is susceptible to the same SQL injection pattern via 'course_year_section', with a public exploit. Instances exposed to the internet should be taken offline or placed behind strict access controls immediately.
9
A path traversal flaw in the ruoyi-vue-pro framework's file upload endpoint allows remote attackers to write files outside the intended directory by manipulating the generated upload path. This can lead to webshell deployment or overwriting of sensitive configuration files on affected servers.
10
A third SQL injection entry point in SourceCodester Class and Exam Timetabling System 1.0 affects /preview4.php via the same 'course_year_section' parameter, with the exploit publicly available. The recurrence of this pattern across multiple endpoints suggests the vulnerability is systemic in this codebase.
Today’s recommendation: Prioritize firmware review and network isolation for all Tenda JD12L devices, and audit any internet-facing deployments of SourceCodester Class and Exam Timetabling System and ruoyi-vue-pro for the disclosed injection and traversal vectors. Where patches are unavailable, restrict administrative and web interfaces to trusted networks and enforce input validation at the perimeter.
Even on a day without active exploitation confirmed in the wild, the volume of public proof-of-concept code published today makes it essential to validate whether any of these affected components exist within your own attack surface before threat actors do it for you.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →Previous briefings
September 8, 2026 — Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 2026 — 22 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026 — Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026 — WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026 — WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026 — Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026 — WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026 — Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026 — WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026 — Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026 — Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 2026 — 10 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026 — Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026 — Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →