Show filters
223 Total Results
Displaying 1-10 of 223
Sort by:
Attacker Value
Unknown
CVE-2022-29953
Disclosure Date: July 26, 2022 (last updated October 07, 2023)
The Bently Nevada 3700 series of condition monitoring equipment through 2022-04-29 has a maintenance interface on port 4001/TCP with undocumented, hardcoded credentials. An attacker capable of connecting to this interface can thus trivially take over its functionality.
1
Attacker Value
Unknown
CVE-2025-1143
Disclosure Date: February 11, 2025 (last updated February 11, 2025)
Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in through the SSH service using these credentials and obtain root privilege of the system.
0
Attacker Value
Unknown
CVE-2024-33056
Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
0
Attacker Value
Unknown
CVE-2024-11983
Disclosure Date: November 29, 2024 (last updated December 21, 2024)
Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject arbitrary system commands into a specific SSH function and execute them on the device.
0
Attacker Value
Unknown
CVE-2024-11982
Disclosure Date: November 29, 2024 (last updated December 21, 2024)
Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers with administrator privileges can access the user settings page to retrieve plaintext passwords.
0
Attacker Value
Unknown
CVE-2024-11981
Disclosure Date: November 29, 2024 (last updated December 21, 2024)
Certain models of routers from Billion Electric has an Authentication Bypass vulnerability, allowing unautheticated attackers to retrive contents of arbitrary web pages.
0
Attacker Value
Unknown
CVE-2024-11980
Disclosure Date: November 29, 2024 (last updated December 21, 2024)
Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device.
0
Attacker Value
Unknown
CVE-2024-23385
Disclosure Date: November 04, 2024 (last updated November 08, 2024)
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
0
Attacker Value
Unknown
CVE-2024-33045
Disclosure Date: September 02, 2024 (last updated September 05, 2024)
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.
0
Attacker Value
Unknown
CVE-2024-23368
Disclosure Date: July 01, 2024 (last updated July 03, 2024)
Memory corruption when allocating and accessing an entry in an SMEM partition.
0