Affected Vendors
- Palo Alto Networks — 12 CVEs (1 high, 11 none/low)
- TRENDnet — 7 CVEs (4 high, 3 medium)
- Cisco — 4 CVEs (4 high)
- OpenWrt / DD-WRT — 2 CVEs (1 high, 1 medium)
- Digi — 1 CVE (none/low)
Critical Vulnerabilities This Week
This week brought 26 new router CVEs, with 10 rated as high severity. The standout threats are concentrated among TRENDnet, Cisco, and OpenWrt deployments, with multiple command injection and privilege escalation flaws requiring immediate attention.
TRENDnet devices face the highest immediate risk. Four high-severity vulnerabilities (CVSS 8.8) affect the TEW-821DAP and TEW-635BRM models. CVE-2026-15484 and CVE-2026-15483 both target the /goform/tools_nslookup endpoint in the TEW-821DAP 1.12B01, allowing buffer overflow attacks. Similarly, CVE-2026-15480 and CVE-2026-15481 impact the TEW-635BRM up to firmware 1.00.03, exploiting the Web Service and IPoA WAN setup functions. Three additional medium-severity flaws (CVE-2026-15485, CVE-2026-15486, CVE-2026-15487) affect the same TEW-821DAP in earlier firmware versions. TRENDnet users should check for available firmware updates immediately and isolate affected devices from untrusted networks until patched.
Cisco RV-series routers have multiple OS command injection vulnerabilities. Four high-severity flaws (CVSS 7.2 each) affect the RV130, RV130W, and RV110W models running the specified firmware versions. CVE-2026-24700, CVE-2026-24697, CVE-2026-24698, and CVE-2026-24699 all allow unauthenticated or low-privilege attackers to inject arbitrary OS commands through various daemon initialization functions. These vulnerabilities could lead to full device compromise. Cisco customers running RV130/RV130W firmware 1.0.3.55 or RV110W firmware 1.2.2.5/1.2.2.8 should prioritize firmware updates and review network access controls.
OpenWrt users need to update the Samba component urgently. CVE-2026-59260 (CVSS 8.8) allows authenticated delegated users to execute the Samba daemon with arbitrary command-line arguments, bypassing intended access controls on the luci-app-samba4 read ACL. This is particularly dangerous in multi-tenant or managed environments. Update to OpenWrt v25.12.5 or later if running affected versions.
Palo Alto Networks has one notable high-severity issue among its 12 total CVEs this week. CVE-2026-0288 (CVSS 7.5) describes multiple buffer overflow vulnerabilities in the User-ID Terminal Server Agent component that could allow unauthenticated remote attackers to cause denial of service or potentially execute code. The remaining 11 Palo Alto CVEs are rated none or low severity but include authentication bypass (CVE-2026-0283) and SSRF (CVE-2026-0285) flaws affecting the Large Scale VPN functionality.
Action items for this week: Audit your network for TRENDnet and Cisco affected models, check firmware versions against the vulnerable ranges listed, and apply patches as soon as available. For OpenWrt deployments, verify Samba4 component versions. Subscribe to vendor security advisories for Palo Alto Networks PAN-OS updates addressing CVE-2026-0288.