Daily briefing · June 28, 2026

Five Tenda Router Buffer Overflows Lead a Day of 47 New CVEs, All with Public Exploits

Automated Vexday summary · sources: NVD, CISA KEV, EPSS

June 28, 2026 brought 47 newly published vulnerabilities, none rated critical and none yet flagged for active exploitation — but five high-severity stack-based buffer overflows in the Tenda JD12L router, all with public proof-of-concept code, demand immediate attention from network defenders. The day's remaining highlights include a dangerous use-after-free in the Zephyr RTOS DNS stack, multiple SQL injection flaws in a widely redistributed open-source academic scheduling system, and a path traversal vulnerability in the ruoyi-vue-pro enterprise framework.

Today’s brief
  • Five Tenda JD12L router CVEs (CVSS 8.7) are all remotely exploitable with public PoC code — patch or isolate these devices now.
  • Zephyr RTOS carries a use-after-free in its async DNS resolver that can corrupt memory in embedded/IoT devices.
  • Three SQL injection flaws in SourceCodester's Class and Exam Timetabling System are publicly disclosed and remotely exploitable.
  • A path traversal bug in ruoyi-vue-pro allows attackers to write files outside intended directories via the file upload endpoint.
0
critical
0
Actively exploited
0
Before CISA
0
Weaponized
Critical highlights
1
CVE-2026-13519HIGH 8.7PoCaffects JD12L
A remotely exploitable stack-based buffer overflow in the Tenda JD12L's NatStaticSetting handler can be triggered by manipulating the 'page' argument. With a public exploit already available, attackers on the internet can attempt to gain control of affected routers without authentication.
2
CVE-2026-13518HIGH 8.7PoCaffects JD12L
The addressNat function of Tenda JD12L firmware 16.03.53.23 is vulnerable to a stack-based buffer overflow via the 'page' parameter, exploitable remotely with a public PoC. This mirrors CVE-2026-13519 in severity and attack surface, widening the risk on the same device.
3
CVE-2026-13517HIGH 8.7PoCaffects JD12L
Manipulation of the 'security_5g' argument in the Tenda JD12L's WifiBasicSet handler triggers a stack overflow, enabling potential remote code execution. The public disclosure of the exploit makes this an immediate risk for any exposed unit.
4
CVE-2026-13516HIGH 8.7PoCaffects JD12L
The WifiGuestSet function in Tenda JD12L is vulnerable to a stack overflow via the 'shareSpeed' parameter, with a publicly available exploit. Organizations using this device for guest network segmentation should treat it as untrusted until patched.
5
CVE-2026-13515HIGH 8.7PoCaffects JD12L
A stack-based buffer overflow in the PPTP server configuration function of Tenda JD12L can be triggered remotely via the 'startIp' parameter. The combination of remote exploitability and public PoC code makes this the fifth high-risk entry point on the same router model.
6
CVE-2026-10646HIGH 7.4affects zephyr
Zephyr's asynchronous DNS resolver passes a pointer to a stack-allocated state object as user data; if the semaphore wait times out before the resolver callback fires, the callback writes into freed stack memory, creating a use-after-free condition. Embedded and IoT systems running Zephyr with network connectivity should be evaluated for exposure, particularly in environments where DNS queries can be influenced externally.
7
CVE-2026-13486MEDIUM 6.9PoCaffects Class and Exam Timetabling System
A SQL injection vulnerability in the 'course_year_section' parameter of /preview6.php in SourceCodester Class and Exam Timetabling System 1.0 is remotely exploitable and publicly disclosed. Attackers can enumerate or exfiltrate the underlying database without special privileges.
8
CVE-2026-13485MEDIUM 6.9PoCaffects Class and Exam Timetabling System
The /preview.php endpoint of SourceCodester Class and Exam Timetabling System 1.0 is susceptible to the same SQL injection pattern via 'course_year_section', with a public exploit. Instances exposed to the internet should be taken offline or placed behind strict access controls immediately.
9
CVE-2026-13528MEDIUM 6.9affects ruoyi-vue-pro
A path traversal flaw in the ruoyi-vue-pro framework's file upload endpoint allows remote attackers to write files outside the intended directory by manipulating the generated upload path. This can lead to webshell deployment or overwriting of sensitive configuration files on affected servers.
10
CVE-2026-13527MEDIUM 6.9affects Class and Exam Timetabling System
A third SQL injection entry point in SourceCodester Class and Exam Timetabling System 1.0 affects /preview4.php via the same 'course_year_section' parameter, with the exploit publicly available. The recurrence of this pattern across multiple endpoints suggests the vulnerability is systemic in this codebase.
Today’s recommendation: Prioritize firmware review and network isolation for all Tenda JD12L devices, and audit any internet-facing deployments of SourceCodester Class and Exam Timetabling System and ruoyi-vue-pro for the disclosed injection and traversal vectors. Where patches are unavailable, restrict administrative and web interfaces to trusted networks and enforce input validation at the perimeter.
Even on a day without active exploitation confirmed in the wild, the volume of public proof-of-concept code published today makes it essential to validate whether any of these affected components exist within your own attack surface before threat actors do it for you.Don’t wait to become a statistic: validate today, at no cost, whether any of these vectors reach your systems.Meet the Autonomous AI Pentest Agent →
Previous briefings
September 8, 2026Windows Under Active Exploit, ScreenConnect Zero-Day Detected Before CISA: September 8 Security BulletinSeptember 7, 202622 Critical CVEs Published on a Quiet Day, With Heavy Ransomware Pressure on BrazilSeptember 6, 2026Quiet Day Hides Real Risks: Tenda HG10, NEC UNIVERGE, and Brazilian Ransomware Surge Demand AttentionSeptember 5, 2026WordPress Plugin Wave and Tenda CP3 Flaws Lead a Calm But CVE-Heavy DaySeptember 4, 2026WordPress Plugins and FreeIPMI Lead a Calm but Patch-Heavy DaySeptember 3, 2026Four CVSS 10.0 Critical CVEs Headline a Calm But Dense Vulnerability DaySeptember 2, 2026WordPress Plugins Under Fire, Cisco IOS XR and NX-OS in the Crosshairs: ATTENTION Day With Active ExploitationSeptember 1, 2026Active Exploitation of Proxmox and SonicWall SMA1000 Leads a High-Alert DayAugust 31, 2026WordPress Plugins and Tenda Routers Dominate a High-Alert Day With 41 Critical CVEsAugust 30, 2026Calm Day Hides Sharp Edges: Critical Code Injection and Router Flaws Top August 30 BulletinAugust 29, 2026Ten Active-Exploitation CVEs Dominate as Ransomware Groups Hammer BrazilAugust 28, 202610 Actively Exploited CVEs Demand Immediate Action: Metabase, VMware, macOS, Cisco, and More Under FireAugust 27, 2026Router Firmware Under Active Exploitation and WordPress Wave Raises Alerts on August 27August 26, 2026Ubiquiti UniFi and Gitea Face Active Exploitation Alerts as 62 Critical CVEs Emergeview full archive →
Share