Show filters
345 Total Results
Displaying 11-20 of 345
Sort by:
Attacker Value
Unknown
CVE-2024-32928
Disclosure Date: August 19, 2024 (last updated August 21, 2024)
The libcurl CURLOPT_SSL_VERIFYPEER option was disabled on a subset of requests made by Nest production devices which enabled a potential man-in-the-middle attack on requests to Google cloud services by any host the traffic was routed through.
0
Attacker Value
Unknown
CVE-2024-42638
Disclosure Date: August 16, 2024 (last updated September 12, 2024)
H3C Magic B1ST v100R012 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.
0
Attacker Value
Unknown
CVE-2024-28947
Disclosure Date: August 14, 2024 (last updated September 13, 2024)
Improper input validation in kernel mode driver for some Intel(R) Server Board S2600ST Family firmware before version 02.01.0017 may allow a privileged user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2024-1623
Disclosure Date: March 14, 2024 (last updated January 24, 2025)
Insufficient session timeout vulnerability in the FAST3686 V2 Vodafone router from Sagemcom. This vulnerability could allow a local attacker to access the administration panel without requiring login credentials. This vulnerability is possible because the 'Login.asp and logout.asp' files do not handle session details correctly.
0
Attacker Value
Unknown
CVE-2024-23910
Disclosure Date: February 28, 2024 (last updated February 15, 2025)
Cross-site request forgery (CSRF) vulnerability in ELECOM wireless LAN routers and wireless LAN repeater allows a remote unauthenticated attacker to hijack the authentication of administrators and to perform unintended operations to the affected product. Note that WMC-X1800GST-B and WSC-X1800GS-B are also included in e-Mesh Starter Kit "WMC-2LX-B".
0
Attacker Value
Unknown
CVE-2024-21798
Disclosure Date: February 28, 2024 (last updated February 15, 2025)
ELECOM wireless LAN routers contain a cross-site scripting vulnerability. Assume that a malicious administrative user configures the affected product with specially crafted content. When another administrative user logs in and operates the product, an arbitrary script may be executed on the web browser. Note that WMC-X1800GST-B is also included in e-Mesh Starter Kit "WMC-2LX-B".
0
Attacker Value
Unknown
CVE-2024-22372
Disclosure Date: January 24, 2024 (last updated September 09, 2024)
OS command injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by sending a specially crafted request to the product.
0
Attacker Value
Unknown
CVE-2023-38587
Disclosure Date: January 19, 2024 (last updated January 31, 2024)
Improper input validation in some Intel NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2023-6339
Disclosure Date: January 02, 2024 (last updated January 10, 2024)
Google Nest WiFi Pro root code-execution & user-data compromise
0
Attacker Value
Unknown
CVE-2023-48419
Disclosure Date: January 02, 2024 (last updated January 10, 2024)
An attacker in the wifi vicinity of a target Google Home can spy on the victim, resulting in Elevation of Privilege
0