SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-28151

HIGH · CVSS 8.1 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-08-24 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Tonda versions prior to 2.6 are vulnerable to an unauthenticated Local File Inclusion (LFI) flaw, allowing attackers to access sensitive files on the server. This vulnerability poses a significant risk as it can lead to information disclosure and potential further exploitation of the system. Organizations using affected versions should prioritize patching to mitigate the risk of unauthorized access to their file systems.

CVE
CVE-2026-28151
Severity
HIGH
CVSS
8.1
EPSS
0.28%

Original NVD Description

Unauthenticated Local File Inclusion in Tonda < 2.6 versions.