Show filters
102 Total Results
Displaying 11-20 of 102
Sort by:
Attacker Value
Unknown
CVE-2024-12642
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
TenderDocTransfer from Chunghwa Telecom has an Arbitrary File Write vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally, one of the APIs contains a Relative Path Traversal vulnerability, allowing attackers to write arbitrary files to any path on the user's system.
0
Attacker Value
Unknown
CVE-2024-12641
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
TenderDocTransfer from Chunghwa Telecom has a Reflected Cross-site scripting vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use specific APIs through phishing to execute arbitrary JavaScript code in the user’s browser. Since the web server set by the application supports Node.Js features, attackers can further leverage this to run OS commands.
0
Attacker Value
Unknown
CVE-2024-43689
Disclosure Date: October 21, 2024 (last updated November 26, 2024)
Stack-based buffer overflow vulnerability exists in ELECOM wireless access points. By processing a specially crafted HTTP request, arbitrary code may be executed.
0
Attacker Value
Unknown
CVE-2024-42412
Disclosure Date: August 30, 2024 (last updated November 26, 2024)
Cross-site scripting vulnerability exists in ELECOM wireless access points due to improper processing of input values in menu.cgi. If a user views a malicious web page while logged in to the product, an arbitrary script may be executed on the user's web browser.
0
Attacker Value
Unknown
CVE-2024-39300
Disclosure Date: August 30, 2024 (last updated September 04, 2024)
Missing authentication vulnerability exists in Telnet function of WAB-I1750-PS v1.5.10 and earlier. When Telnet function of the product is enabled, a remote attacker may login to the product without authentication and alter the product's settings.
0
Attacker Value
Unknown
CVE-2024-34577
Disclosure Date: August 30, 2024 (last updated September 04, 2024)
Cross-site scripting vulnerability exists in WRC-X3000GS2-B, WRC-X3000GS2-W, and WRC-X3000GS2A-B due to improper processing of input values in easysetup.cgi. If a user views a malicious web page while logged in to the product, an arbitrary script may be executed on the user's web browser.
0
Attacker Value
Unknown
CVE-2024-40883
Disclosure Date: August 01, 2024 (last updated November 26, 2024)
Cross-site request forgery vulnerability exists in ELECOM wireless LAN routers. Viewing a malicious page while logging in to the affected product with an administrative privilege, the user may be directed to perform unintended operations such as changing the login ID, login password, etc.
0
Attacker Value
Unknown
CVE-2024-39607
Disclosure Date: August 01, 2024 (last updated November 26, 2024)
OS command injection vulnerability exists in ELECOM wireless LAN routers. A specially crafted request may be sent to the affected product by a logged-in user with an administrative privilege to execute an arbitrary OS command.
0
Attacker Value
Unknown
CVE-2024-34021
Disclosure Date: August 01, 2024 (last updated November 26, 2024)
Unrestricted upload of file with dangerous type vulnerability exists in ELECOM wireless LAN routers. A specially crafted file may be uploaded to the affected product by a logged-in user with an administrative privilege, resulting in an arbitrary OS command execution.
0
Attacker Value
Unknown
CVE-2024-36103
Disclosure Date: June 12, 2024 (last updated June 12, 2024)
OS command injection vulnerability in WRC-X5400GS-B v1.0.10 and earlier, and WRC-X5400GSA-B v1.0.10 and earlier allows a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by sending a specially crafted request to the product.
0