CVE-2026-21549: In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed
Details
Original advisory: https://nvd.nist.gov/vuln/detail/CVE-2026-21549
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-215490.40% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-21549 | coverage & exploitation status | NVD · CVE.org |
Recent advisories for In modem
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- highCVE-2026-21555: In modem, there is a possible improper input validation. This could lead to remote denial of s…nvd · 2026-08-03
- highCVE-2026-21554: In modem, there is a possible improper input validation. This could lead to remote denial of s…nvd · 2026-08-03
- highCVE-2026-21553: In modem, there is a possible improper input validation. This could lead to remote denial of s…nvd · 2026-08-03
- highCVE-2026-21552: In modem, there is a possible improper input validation. This could lead to remote denial of s…nvd · 2026-08-03
- highCVE-2026-21551: In modem, there is a possible improper input validation. This could lead to remote denial of s…nvd · 2026-08-03
- highCVE-2026-21550: In modem, there is a possible improper input validation. This could lead to remote denial of s…nvd · 2026-08-03
More from NVD Recent CVEs
- unknownCVE-2026-9487: XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_x…2026-08-03
- unknownCVE-2026-9390: XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_si…2026-08-03
- highCVE-2026-69097: GitPython before 3.1.53 fails to properly escape section names in git config files, allowing a…2026-08-03
- highCVE-2026-69096: OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docke…2026-08-03
- highCVE-2026-69095: OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path t…2026-08-03