CWE-354

CWE-354 · 5 records · 4 with a public proof-of-concept

Records the NVD classes under CWE-354, highest CVSS first.

  1. HIGH 8.8CVE-2026-76852public PoC

    Netcore NR268 firmware version 1.7.121109 has an improper integrity verification flaw in mtd_write allowing forged firmware authenticity checks. Attackers can exploit put_file.cgi and check_image_uuid.c to bypass firmware signature validation and load unauthor…

    AI risk analysis on Exploit-DB.ai →

  2. HIGH 7.4CVE-2026-73459

    On affected platforms running Arista EOS with IS-IS configured, an unauthenticated attacker who can inject a specially crafted IS-IS LSP PDU can cause the legitimate LSP to be unexpectedly purged from the IS-IS link-state database. This may result in traffic l…

    AI risk analysis on Exploit-DB.ai →

  3. MEDIUM 5.9CVE-2026-95625public PoC

    The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes. The update manifest -- which contains the version number, download URL, and signature -- is fetched over TLS but is never itself si…

    AI risk analysis on Exploit-DB.ai →

  4. UNSCOREDCVE-2026-54580public PoC

    mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/util.c did not make every truncated, corrupt, or failed zstd stream fatal in mport_decompress_zstd(), and libmport/fetch.c did not consistently propagate those failures to index-fetch callers. …

    AI risk analysis on Exploit-DB.ai →

  5. UNSCOREDCVE-2026-54578public PoC

    mport is the MidnightBSD Package Manager. Prior to 2.7.8, mport_verify_package() in libmport/verify.c could continue after MD5File() or SHA256_File() failed and compare an expected checksum with stale data in the hash buffer rather than a newly computed digest…

    AI risk analysis on Exploit-DB.ai →