By weakness (CWE)

CWE-134: related vulnerabilities

CVEs classified under CWE-134. Understanding the weakness class helps prioritize systemic fixes over one-off patches.

5 published vulnerabilities

  • CVE-2026-12174HIGH 8.8

    D-Link DCS-935L cameras running firmware version 1.10.01 contain a format string vulnerability in their web interface. An attacker with valid login credentials can send specially crafted requests to a specific CGI handler to read sensitive memory, modify system behavior, or execute code on the device. The vulnerability requires authentication but offers no other barriers; it can be exploited over the network without user interaction.

  • CVE-2026-57877HIGH 8.6

    GeoVision's network video recording devices (GV-LPC2011 and GV-LPC2211, version 1.12 and earlier) contain a format string vulnerability in their login service that can be exploited without authentication. An attacker can send specially crafted login requests over the network to trigger memory corruption, leak sensitive information, or crash the service. The flaw stems from unsafe handling of user-supplied data when constructing log messages during login attempts.

  • CVE-2026-6250HIGH 8.1

    A flaw in the ONVIF service of TP-Link Tapo C110 v2 cameras allows an authenticated attacker to trigger a factory reset by exploiting how the device processes user input. When the device interprets attacker-supplied data as a format string—a type of code injection—an attacker can manipulate memory to redirect the camera to reset itself, erasing all saved configurations, login credentials, and effectively disabling the device until reconfiguration.

  • CVE-2025-10262MEDIUM 6.3

    CVE-2025-10262 is a local privilege escalation flaw in Nokia SR Linux that stems from improper validation of format strings. An authenticated user with limited privileges can exploit this weakness to gain superuser-level command execution on the device. The vulnerability requires local access and cannot be exploited remotely, but once triggered, it grants full system control.

  • CVE-2026-46465MEDIUM 5.5

    Dell PowerProtect Data Domain contains a format string vulnerability that allows a high-privileged attacker with network access to trigger information disclosure or crash the system. While the vulnerability requires elevated privileges to exploit, its presence in backup and archival infrastructure—often a critical dependency—warrants careful monitoring and timely patching.