CVE-2026-63424
During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authentic
CVSS
7.3
High
EPSS
0.1%
p1
KEV
—
Exploit Today
0
0-100
Published: Aug 13, 2026 · Last modified: Aug 24, 2026 · CWE-261
0.1%EPSS · 30 days0.1%
2026-08-142026-08-31
During an internal security assessment, an improperly protected key was discovered in Lenovo Dock Manager that could allow a local authenticated user to escalate privileges.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-675966.2 MED1.3%
——0CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all stored secrets in plaintext by reversing a single-byte XOR cipher that uses a static key to obfuscate the configuration backup file. Attackers can trivially decrypt the Router.cfg backup file to expose web administration and telnet passwords, WPA/WPA2 pre-shared keys, PPPoE and 3G/APN credentials, and SIM identifiers including IMSI and IMEI.31dCVE-2026-406395.7 MED8.9%
——3Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges.39dCVE-2026-25607—0.8%
——0Use of a weak password encoding algorithm in STER software allows the value of the password to be guessed after analyzing how passwords with known values are encoded.
This issue was fixed in version 9.5.39d