VU#564823: GNU Wget enables SSRF via unvalidated FTP PASV IPs

2026-07-10T20:52:15Z722d2e5871405433c743409368aba210119845e1bb4294f3ab96a29b436a0a40
APIAndroidCORSFTPIoTJWTJavaScript-injectionPASVRCESSRFTLS/SSLWebViewWgetanti-cheatauthentication-bypassbackdoorcertificate-bypassdata-exposurekernel-driverlocal-exploitmissing-authorizationmobileprinterprivilege-escalationrouter

What happened

Collection of CERT/CC vulnerability advisories covering multiple distinct issues: GNU Wget FTP PASV SSRF (CVE-2026-15146); PayRange Android WebView TLS bypass and JavaScript injection (CVE-2026-13462, CVE-2026-13461); Xerte Online Toolkits authentication bypass and RCE (CVE-2026-14261, CVE-2026-12116); Adalo platform-wide data exposure and long-lived JWT reuse (CVE-2026-10706, CVE-2026-10708); Tenda firmware undocumented backdoor bypassing authentication (CVE-2026-11405); HP DeskJet 2800 series missing authorization (CVE-2026-13753); and multiple local privilege escalations in the Little Orbit

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
722d2e5871405433c743409368aba210119845e1bb4294f3ab96a29b436a0a40
Enrichment time
2026-07-10T20:52:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · VU#564823: GNU Wget enables SSRF via unvalidated FTP PASV IPs · Baitaphish