Aug 29, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2022-32548 Draytek Vigor1000b Firmware Buffer Overflow

  • CVSS 10

New critical Draytek Vigor1000b Firmware Buffer Overflow (CVSS 10) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-36553 Hytec Hwl-2511-ss Firmware Command Injection

  • CVSS 9.8

New critical Hytec Hwl-2511-ss Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2022-36554 Hytec Hwl-2511-ss Firmware Command Injection

  • CVSS 9.8

New critical Hytec Hwl-2511-ss Firmware Command Injection (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2022-32548 CVSS 10

An issue was discovered on certain DrayTek Vigor routers before July 2022 such as the Vigor3910 before 4.3.1.1.

CVE-2022-32993 CVSS 9.8

TOTOLINK A7000R V4.1cu.4134 was discovered to contain an access control issue via /cgi-bin/ExportSettings.sh.

CVE-2022-36553 CVSS 9.8

Hytec Inter HWL-2511-SS v1.05 and below was discovered to contain a command injection vulnerability via the component /www/cgi-bin/popen....

CVE-2022-36554 CVSS 9.8

A command injection vulnerability in the CLI (Command Line Interface) implementation of Hytec Inter HWL-2511-SS v1.05 and below allows at...

CVE-2022-36555 CVSS 9.8

Hytec Inter HWL-2511-SS v1.05 and below implements a SHA512crypt hash for the root account which can be easily cracked via a brute-force...

CVE-2022-36556 CVSS 9.8

Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at...

CVE-2022-36557 CVSS 9.8

Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup fun...

CVE-2022-36558 CVSS 9.8

Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account.

CVE-2022-36559 CVSS 9.8

Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain a command injection vulnerability via the Ping parameter at ping_ex...

CVE-2022-36560 CVSS 9.8

Seiko SkyBridge MB-A200 v01.00.04 and below was discovered to contain multiple hard-coded passcodes for root.

View critical disclosures

cvelogic Threat Intelligence