LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-28681

CVE-2026-28681 - Vulnerability Analysis

HighCVSS: 8.1

Last Updated: March 9, 2026

Internet Routing Registry daemon - Open Redirect & Account Takeover

Published: March 6, 2026Updated: March 9, 2026Remote Exploitable

Overview

Internet Routing Registry daemon 4.4.0 to <4.4.5 and 4.5.0 to <4.5.1 contains an open redirect caused by HTTP Host header manipulation in password reset and account creation, letting attackers hijack accounts via confirmation link, exploit requires victim to open attacker-controlled link.

Severity & Score

Severity: High
CVSS Score: 8.1
EPSS Score: 5.5%(Probability of exploitation in next 30 days)

Impact

Attackers can take over user accounts and modify RPSL objects, potentially impacting network routing data integrity.

Mitigation

Update to versions 4.4.5 or 4.5.1 or later.

Social Media Activity(2 posts)

TheHackerWire
TheHackerWire
@thehackerwire
Mar 6, 2026

🟠 CVE-2026-28681 - High (8.1) Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from version 4.5.0 to before version 4.5.1, an attacker can manipulate the HTTP Host he... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-28681/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post
TheHackerWire
TheHackerWire
@thehackerwire
Mar 6, 2026

🟠 CVE-2026-28681 - High (8.1) Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from version 4.5.0 to before version 4.5.1, an attacker can manipulate the HTTP Host he... šŸ”— https://www.thehackerwire.com/vulnerability/CVE-2026-28681/ #CVE #vulnerability #infosec #cybersecurity #security #Tenda #patchstack

View original post

Details

CVE ID
CVE-2026-28681
Severity
High
CVSS Score
8.1
Type
open_redirect
Status
unconfirmed
EPSS
5.5%
Social Posts
2

CWE

  • CWE-601

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

EPSS Score

5.5%Probability of exploitation in the next 30 days