Entry Thumbnail

Canva Affinity EMF File EMR_HEADER offDescription Out-Of-Bounds Read Vulnerability

CVE-2025-61979 An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information. The versions below were either tested or verified to be vulnerable […]

Posted by
Entry Thumbnail

Canva Affinity EMF File EMR_HEADER nDescription Out-Of-Bounds Read Vulnerability

CVE-2025-62500 An out-of-bounds read vulnerability exists in the EMF functionality of Canva Affinity. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information. The versions below were either tested or verified to be vulnerable […]

Posted by
Entry Thumbnail

Tp-Link AX53 v1.0 tmpServer opcode 0x429 stack-based buffer overflow vulnerability

CVE-2025-62405 A stack-based buffer overflow vulnerability exists in the tmpServer SmartNetSetClientList() functionality of Tp-Link AX53 v1.0 1.3.1 Build 20241120 rel.54901(5553). A specially crafted set of network packets can lead to arbitrary code execution. An attacker can send packets to trigger this vulnerability. The versions below were either tested or verified […]

Posted by
Entry Thumbnail

Tp-Link AX53 v1.0 tmpServer opcode 0x1003 stack-based buffer overflow vulnerability

CVE-2025-58455 A stack-based buffer overflow vulnerability exists in the tmpServer opcode 0x1003 functionality of Tp-Link AX53 v1.0 1.3.1 Build 20241120 rel.54901(5553). A specially crafted network packets can lead to arbitrary code execution. An attacker can send packets to trigger this vulnerability. The versions below were either tested or verified to […]

Posted by
Entry Thumbnail

Tp-Link AX53 v1.0 tdpServer ssh port update stack-based buffer overflow vulnerability

CVE-2025-62673 A stack-based buffer overflow vulnerability exists in the tdpServer ssh port update functionality of Tp-Link AX53 v1.0 1.3.1 Build 20241120 rel.54901(5553). A specially crafted network packet can lead to stack-based buffer overflow. An attacker can send a packet to trigger this vulnerability. The versions below were either tested or […]

Posted by
Entry Thumbnail

RIP RegPwn

13th March 2026 As part of MDSec’s R&D work, we often discover vulnerabilities and develop exploits to support our red team engagements. When researching widely used software, it is often only a matter of time before the same vulnerability is discovered by other researchers and reported to the vendor. Two […]

Posted by