An in-depth analysis of two vulnerabilities found in Netis MEX605 router firmware v2.00.06: OS command injection via the ping diagnostic tool, and DOM-based XSS in the NTP server configuration.
A command injection vulnerability found in the WPS PIN handling of the E5600 router — authenticated remote code execution via a crafted WPS PIN parameter