Show filters
43 Total Results
Displaying 11-20 of 43
Sort by:
Attacker Value
Unknown
CVE-2022-26997
Disclosure Date: March 15, 2022 (last updated October 07, 2023)
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the upnp function via the upnp_ttl parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
0
Attacker Value
Unknown
CVE-2022-26996
Disclosure Date: March 15, 2022 (last updated October 07, 2023)
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pppoe function via the pppoe_username, pppoe_passwd, and pppoe_servicename parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
0
Attacker Value
Unknown
CVE-2022-26995
Disclosure Date: March 15, 2022 (last updated October 07, 2023)
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the pptp (wan_pptp.html) function via the pptp_fix_ip, pptp_fix_mask, pptp_fix_gw, and wan_dns1_stat parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
0
Attacker Value
Unknown
CVE-2021-41552
Disclosure Date: February 15, 2022 (last updated October 07, 2023)
CommScope SURFboard SBG6950AC2 9.1.103AA23 devices allow Command Injection.
0
Attacker Value
Unknown
CVE-2021-20119
Disclosure Date: November 09, 2021 (last updated October 07, 2023)
The password change utility for the Arris SurfBoard SB8200 can have safety measures bypassed that allow any logged-in user to change the administrator password.
0
Attacker Value
Unknown
CVE-2021-20120
Disclosure Date: October 21, 2021 (last updated November 28, 2024)
The administration web interface for the Arris Surfboard SB8200 lacks any protections against cross-site request forgery attacks. This means that an attacker could make configuration changes (such as changing the administrative password) without the consent of the user.
0
Attacker Value
Unknown
CVE-2021-33219
Disclosure Date: July 07, 2021 (last updated November 28, 2024)
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. There are Hard-coded Web Application Administrator Passwords for the admin and nplus1user accounts.
0
Attacker Value
Unknown
CVE-2021-33216
Disclosure Date: July 07, 2021 (last updated November 28, 2024)
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer account.
0
Attacker Value
Unknown
CVE-2021-33215
Disclosure Date: July 07, 2021 (last updated November 28, 2024)
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The API allows Directory Traversal.
0
Attacker Value
Unknown
CVE-2021-33217
Disclosure Date: July 07, 2021 (last updated November 28, 2024)
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. The Web Application allows Arbitrary Read/Write actions by authenticated users. The API allows an HTTP POST of arbitrary content into any file on the filesystem as root.
0