Jun 3, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Contec Sv-cpt-mc310 Firmware: public exploit or PoC linked (Directory Traversal)
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Active exploit activity

CVE-2021-46422 Telesquare Sdt-cs3b1 Firmware Command Injection

  • Public exploit or PoC available
  • Exploit activity linked

Telesquare Sdt-cs3b1 Firmware Command Injection now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Active exploit activity

CVE-2022-29298 SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.

  • Public exploit or PoC available
  • Exploit activity linked

Contec Sv-cpt-mc310 Firmware Directory Traversal now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.

Critical exposure

CVE-2021-42884 Totolink Ex1200t Firmware Command Injection

  • CVSS 9.8

New critical Totolink Ex1200t Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

CVE-2022-29298 Exploit

SolarView Compact ver.6.00 allows attackers to access sensitive files via directory traversal.

CVE-2022-30525 Exploit

Zyxel Multiple Firewalls OS Command Injection

CVE-2022-1631 Exploit

Users Account Pre-Takeover or Users Account Takeover.

CVE-2022-1588 Exploit

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER.

CVE-2021-46422 Exploit

Telesquare SDT-CW3B1 1.1.0 is affected by an OS command injection vulnerability that allows a remote attacker to execute OS commands with...

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-42884 CVSS 9.8

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceName of the file global.so which ca...

CVE-2021-42885 CVSS 9.8

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setDeviceMac of the file global.so which can...

CVE-2021-42887 CVSS 9.8

In TOTOLINK EX1200T V4.1.2cu.5215, an attacker can bypass login by sending a specific request through formLoginAuth.htm.

CVE-2021-42888 CVSS 9.8

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function setLanguageCfg of the file global.so which c...

CVE-2021-42890 CVSS 9.8

TOTOLINK EX1200T V4.1.2cu.5215 contains a remote command injection vulnerability in function NTPSyncWithHost of the file system.so which...

CVE-2022-26134 CVSS 9.8

Atlassian Confluence Server and Data Center Remote Code Execution

CVE-2022-26493 CVSS 9.8

Xecurify's miniOrange Premium, Standard, and Enterprise Drupal SAML SP modules possess an authentication and authorization bypass vulnera...

CVE-2022-32269 CVSS 9.8

In Real Player 20.0.8.310, the G2 Control allows injection of unsafe javascript: URIs in local HTTP error pages (displayed by Internet Ex...

CVE-2022-32270 CVSS 9.8

In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Traversal, leading to...

CVE-2022-32271 CVSS 9.6

In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability.

View critical disclosures

cvelogic Threat Intelligence