GUARDED 5 min read 10 Aug 2026

Multiple vulnerabilities in Omada Leads Today's Security Review

Threat Level: Guarded Tags: cve-2025-15627, cve-2025-15628, cve-2025-15629, cwe-798, cve-2026-10849, cwe-122, cwe-787, cve-2026-15314, cwe-120, cve-2026-15895

Key findings
01
Multiple vulnerabilities in Omada
HIGH
CVE coverage: CVE-2025-15627, CVE-2025-15628, CVE-2025-15629. The cited advisories disclose: The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption; devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices.
02
The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c).
HIGH
The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). The buffer is sized to hold the received body bytes but reserves no space for a terminating NUL.
03
Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy.
HIGH
Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service process to crash.
04
Still active: jsii-diff: Command Injection via npm: package argument
HIGH
First reported 2026-08-08; ongoing coverage. jsii-diff: Command Injection via npm: package argument. CVE coverage: CVE-2026-15895, GHSA-wcx4-wpfv-mc5c.
05
NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure.
MEDIUM
NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure. The assigned identifier is CVE-2026-47619.
06
A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /social/ajax.php?action=signup.
MEDIUM
A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /social/ajax.php?action=signup. The assigned identifier is CVE-2026-19211.
07
The account locking mechanism fails to trigger when secondary user stores are inaccessible.
MEDIUM
The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attempt authentication with invalid credentials without triggering the lockout mechanism for users within active stores.
08
Still active: Metabase SQLi zero-day exploited in customer data-theft attacks
INFO
First reported 2026-08-08; ongoing coverage. A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...].

Executive assessment

Today's brief leads with Multiple vulnerabilities in Omada. All 8 selected findings retain their own technical scope, action, observed status, and evidence limits.

Finding 01 — Multiple vulnerabilities in Omada

What changed: CVE coverage: CVE-2025-15627, CVE-2025-15628, CVE-2025-15629. The cited advisories disclose: The protocol relies on hard-coded cryptographic keys to establish trust and protect authentication exchanges between controllers and managed devices during device adoption; devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices.

Technical evidence: CVE-2025-15628; CVSS v4.0 8.2; weakness ['CWE-798']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2025-15628 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2025-15627>)

Finding 02 — The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c).

What changed: The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in response_json_cb() (subsys/mgmt/hawkbit/hawkbit.c). The buffer is sized to hold the received body bytes but reserves no space for a terminating NUL.

Technical evidence: CVE-2026-10849; CVSS v3.1 8.2; weakness ['CWE-122', 'CWE-787']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-10849 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-10849>)

Finding 03 — Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy.

What changed: Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insufficient input validation before memory copy operations. This may lead to buffer overflow condition, causing the web service process to crash.

Technical evidence: CVE-2026-15314; CVSS v4.0 7.1; weakness ['CWE-120']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-15314 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-15314>)

Finding 04 — Still active: jsii-diff: Command Injection via npm: package argument

Coverage status: First reported 2026-08-08; ongoing coverage.

What changed: jsii-diff: Command Injection via npm: package argument. CVE coverage: CVE-2026-15895, GHSA-wcx4-wpfv-mc5c.

Technical evidence: CVE-2026-15895; CVSS v4.0 8.4; weakness ['CWE-78']; technical confidence High.

Why it matters: The High priority moves this beyond routine tracking and requires exposure validation, remediation, and compromise assessment.

Observed status: The cited source reports an active supply-chain compromise; exposure depends on use of the affected packages rather than exploitation of a single vulnerability.

Action: Map CVE-2026-15895 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: github.com](<https://github.com/advisories/GHSA-wcx4-wpfv-mc5c>)

Finding 05 — NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure.

What changed: NVIDIA Dynamo for Linux examples and recipes contain a vulnerability where an attacker could cause a system failure. A successful exploit of this vulnerability might lead to code execution, data tampering, denial of service, and information disclosure.

Technical evidence: CVE-2026-47619; CVSS v3.1 6.6; weakness ['CWE-1357']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-47619 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-47619>)

Finding 06 — A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /social/ajax.php?action=signup.

What changed: A vulnerability was found in SourceCodester Photo Share Website 1.0. This affects an unknown function of the file /social/ajax.php?action=signup.

Technical evidence: CVE-2026-19211; CVSS v4.0 6.9; weakness ['CWE-89', 'CWE-74']; technical confidence Medium.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2026-19211 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2026-19211>)

Finding 07 — The account locking mechanism fails to trigger when secondary user stores are inaccessible.

What changed: The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for account locking if it cannot reach all configured user stores, allowing an attacker to repeatedly attempt authentication with invalid credentials without triggering the lockout mechanism for users within active stores.

Technical evidence: CVE-2024-6832; CVSS v3.1 5.9; weakness ['CWE-693']; technical confidence High.

Why it matters: The Medium priority requires exposure validation and scheduled remediation through normal change control.

Observed status: Observed in-the-wild exploitation status is unknown.

Action: Map CVE-2024-6832 to owned assets, confirm the affected and fixed versions in the cited source, deploy the applicable remediation, and retain evidence of the exposure decision.

Evidence limits: exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: nvd.nist.gov](<https://nvd.nist.gov/vuln/detail/CVE-2024-6832>)

Finding 08 — Still active: Metabase SQLi zero-day exploited in customer data-theft attacks

Coverage status: First reported 2026-08-08; ongoing coverage.

What changed: A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...].

Why it matters: Reported active exploitation elevates this above routine patching: validate exposure immediately, remediate, and assess for prior compromise.

Observed status: The cited source reports active in-the-wild exploitation; independent corroboration (CISA KEV or grounded vendor data) is not yet available.

Action: Review the cited source, validate exposure of the affected technology in owned environments, apply available vendor guidance, and retain evidence of the exposure decision.

Evidence limits: grounded severity unavailable

exploitation status unknown

fixed version or patch state unknown

affected product not structured

[Evidence source: www.bleepingcomputer.com](<https://www.bleepingcomputer.com/news/security/framework-tally-disclose-metabase-data-theft-attacks/>)

cve-2024-6832cve-2025-15627cve-2025-15628cve-2025-15629cve-2026-10849cve-2026-15314cve-2026-15895cve-2026-19211cve-2026-47619cwe-120

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.