Entry Thumbnail

White Eagle Withdraw Drain

# White Eagle withdraw drain via spot-price-based WEGL payout On 2026-05-07 08:14:47 UTC, the White Eagle withdrawal contract on BNB Chain was exploited through a spot-price manipulation logic flaw in its withdrawal path. The attacker used an orchestrator plus 11 helper contracts to call `withdraw()` repeatedly, then sold each WEGL […]

Posted by
Entry Thumbnail

Tp-Link Archer AX53 v1.0 dnsmasq configuration restore TFTP server enable vulnerability

CVE-2026-30817 An external config control vulnerability exists in the Openvpn configuration restore route_up functionality of Tp-Link Archer AX53 v1.0 1.3.1 Build 20241120 rel.54901(5553). A specially crafted configuration value can lead to arbitrary file reading. An attacker can upload a malicious file to trigger this vulnerability. The versions below were either […]

Posted by
Entry Thumbnail

Tp-Link Archer AX53 v1.0 Openvpn configuration restore script_security OS command injection vulnerability

CVE-2026-30815 An os command injection vulnerability exists in the Openvpn configuration restore script_security functionality of Tp-Link Archer AX53 v1.0 1.3.1 Build 20241120 rel.54901(5553). A specially crafted configuration value can lead to arbitrary command execution. An attacker can upload a malicious file to trigger this vulnerability. The versions below were either […]

Posted by
Entry Thumbnail

Tp-Link Archer AX53 v1.0 Openvpn configuration restore client_connect OS command injection vulnerability

CVE-2026-30815 An os command injection vulnerability exists in the Openvpn configuration restore client_connect functionality of Tp-Link Archer AX53 v1.0 1.3.1 Build 20241120 rel.54901(5553). A specially crafted configuration value can lead to arbitrary command execution. An attacker can upload a malicious file to trigger this vulnerability. The versions below were either […]

Posted by
Entry Thumbnail

Norton Secure VPN Installation Insecure Operation On Junction Privilege Escalation Vulnerability

CVE-2025-58074 A privilege escalation vulnerability exists during the installation of Norton Secure VPN via the Microsoft Store. A low-privilege user can replace files during the installation process, which may result in deletion of arbitrary files that can lead to elevation of privileges. The versions below were either tested or verified […]

Posted by