Nov 22, 2022 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical exposure

CVE-2020-23583 OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution.

  • CVSS 9.8
  • Remote code execution exposure

New critical Optilinknetwork Op-xt71000n Firmware RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2020-23584 Optilinknetwork Op-xt71000n Firmware RCE

  • CVSS 9.8
  • Remote code execution exposure

New critical Optilinknetwork Op-xt71000n Firmware RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2020-23591 New critical Optilinknetwork Op-xt71000n Firmware DoS disclosed.

  • CVSS 9.8

New critical Optilinknetwork Op-xt71000n Firmware DoS (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Nothing flagged in this category for this digest.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2020-23583 CVSS 9.8

OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution.

CVE-2020-23584 CVSS 9.8

Unauthenticated remote code execution in OPTILINK OP-XT71000N, Hardware Version: V2.2 occurs when the attacker passes arbitrary commands...

CVE-2020-23591 CVSS 9.8

New critical Optilinknetwork Op-xt71000n Firmware DoS disclosed.

CVE-2022-39070 CVSS 9.8

There is an access control vulnerability in some ZTE PON OLT products.

CVE-2022-43212 CVSS 9.8

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the orderId parameter at fetchOrderData.php.

CVE-2022-43213 CVSS 9.8

Billing System Project v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at editorder.php.

CVE-2022-44807 CVSS 9.8

D-Link DIR-882 1.10B02 and 1.20B06 is vulnerable to Buffer Overflow via webGetVarString.

CVE-2022-44808 CVSS 9.8

A command injection vulnerability has been found on D-Link DIR-823G devices with firmware version 1.02B03 that allows an attacker to exec...

View critical disclosures

cvelogic Threat Intelligence