CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
CPAN 2.35 – Add verify_SSL=>1 to HTTP::Tiny to verify https server identity
CPAN.pm before 2.35 does not verify TLS certificates when downloading distributions over HTTPS.
CPAN 2.35 – Add verify_SSL=>1 to HTTP::Tiny to verify https server identity
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link DIR-X3260 routers. Authentication is not required to exploit this vulnerability.
This vulnerability allows network-adjacent attackers to compromise the integrity of downloaded information on affected installations of multiple NETGEAR routers. Authentication is not required to exploit this vulnerability.
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Authentication is not required to exploit this vulnerability.