VU#308749: Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers

2026-08-25T20:52:01Z8fbbd85d06278f51197f6cf5afe798bf1c01bff01f3c6acdcfdcb34a490a356e
CVE-2026-18412CVE-2026-18497CVE-2026-19505CVE-2026-19506CVE-2026-19874CVE-2026-19912CVE-2026-19913CVE-2026-6726CVE-2026-6727CVE-2026-75501CERT/CCKalturaMetal-Gear-OnlineOpenCartRDK-BTPMarbitrary-file-readauthentication-bypassbuffer-overflowdirectory-traversalinformation-disclosureinsecure-deserializationmemory-corruptionmissing-authenticationremote-code-executionroutersstb-truetypetiming-side-channelvulnerability-disclosureweb-application

What happened

CERT/CC advisories report multiple vulnerabilities across Kaltura HTML5 Player, Metal Gear Online 3, Calix GS7 routers, RDK-B WebUI, TPM 2.0 reference code, OpenCart, and stb_truetype. Impacts include remote code execution, arbitrary file read, authentication bypass, unauthorized router port mapping, memory corruption, cryptographic information leakage, directory traversal, denial of service, and information disclosure.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
certcc_vulnotes
Record identifier
8fbbd85d06278f51197f6cf5afe798bf1c01bff01f3c6acdcfdcb34a490a356e
Enrichment time
2026-08-25T20:52:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.