Show filters
21 Total Results
Displaying 11-20 of 21
Sort by:
Attacker Value
Unknown

CVE-2021-30231

Disclosure Date: April 29, 2021 (last updated February 22, 2025)
The api/zrDm/set_ZRElink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the bssaddr, abiaddr, devtoken, devid, elinksync, or elink_proc_enable parameter.
Attacker Value
Unknown

CVE-2021-30230

Disclosure Date: April 29, 2021 (last updated February 22, 2025)
The api/ZRFirmware/set_time_zone interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the zonename parameter.
Attacker Value
Unknown

CVE-2021-30229

Disclosure Date: April 29, 2021 (last updated February 22, 2025)
The api/zrDm/set_zrDm interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the dm_enable, AppKey, or Pwd parameter.
Attacker Value
Unknown

CVE-2021-30232

Disclosure Date: April 29, 2021 (last updated February 22, 2025)
The api/ZRIGMP/set_IGMP_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the IGMP_PROXY_WAN_CONNECT parameter.
Attacker Value
Unknown

CVE-2021-30233

Disclosure Date: April 29, 2021 (last updated February 22, 2025)
The api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the iptv_vlan parameter.
Attacker Value
Unknown

CVE-2021-25812

Disclosure Date: April 29, 2021 (last updated February 22, 2025)
Command injection vulnerability in China Mobile An Lianbao WF-1 1.01 via the 'ip' parameter with a POST request to /api/ZRQos/set_online_client.
Attacker Value
Unknown

CVE-2021-30234

Disclosure Date: April 29, 2021 (last updated February 22, 2025)
The api/ZRIGMP/set_MLD_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the MLD_PROXY_WAN_CONNECT parameter.
Attacker Value
Unknown

CVE-2019-1010136

Disclosure Date: July 19, 2019 (last updated November 27, 2024)
ChinaMobile GPN2.4P21-C-CN W2001EN-00 is affected by: Incorrect Access Control - Unauthenticated Remote Reboot. The impact is: PLC Wireless Router's are vulnerable to an unauthenticated remote reboot due. The component is: Reboot settings are available to unauthenticated users instead of only authenticaed users. The attack vector is: Remote.
0
Attacker Value
Unknown

CVE-2019-6282

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have CSRF via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.
0
Attacker Value
Unknown

CVE-2019-6279

Disclosure Date: March 21, 2019 (last updated November 27, 2024)
ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnerability via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an Attacker to change the Wireless Security Password.
0