CVE-2025-37147High· 7.1▾ TwilightA Secure Boot Bypass Vulnerability exists in affected Access Points that allows an adversary to bypass the hardware root of trust verification in place to ensure only vendor-signed firmware can execute on the device. An adversary can exp…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
A Secure Boot Bypass Vulnerability exists in affected Access Points that allows an adversary to bypass the hardware root of trust verification in place to ensure only vendor-signed firmware can execute on the device. An adversary can exploit this vulnerability to run modified or custom firmware on affected Access Points.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14327High· 7.5Spoofing issue in the Downloads Panel component
CVE-2025-65046Low· 3.1Microsoft Edge (Chromium-based) Spoofing Vulnerability
CVE-2025-69258Critical· 9.8A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM…
CVE-2026-58575High· 8.8Dell PowerStore contains an Authentication Bypass by Spoofing vulnerability
CVE-2018-25317Critical· 9.8Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation
CVE-2025-3029High· 7.3A crafted URL containing specific Unicode characters could have hidden the true origin of the page, resulting in a potential spoofing attack