Show filters
24 Total Results
Displaying 11-20 of 24
Sort by:
Attacker Value
Unknown

CVE-2020-23583

Disclosure Date: November 23, 2022 (last updated December 22, 2024)
OPTILINK OP-XT71000N V2.2 is vulnerable to Remote Code Execution. The issue occurs when the attacker sends an arbitrary code on "/diag_ping_admin.asp" to "PingTest" interface that leads to COMMAND EXECUTION. An attacker can successfully trigger the COMMAND and can compromise full system.
Attacker Value
Unknown

CVE-2020-23585

Disclosure Date: November 23, 2022 (last updated December 22, 2024)
A remote attacker can conduct a cross-site request forgery (CSRF) attack on OPTILINK OP-XT71000N Hardware Version: V2.2 , Firmware Version: OP_V3.3.1-191028. The vulnerability is due to insufficient CSRF protections for the "mgm_config_file.asp" because of which attacker can create a crafted "csrf form" which sends " malicious xml data" to "/boaform/admin/formMgmConfigUpload". the exploit allows attacker to "gain full privileges" and to "fully compromise of router & network".
Attacker Value
Unknown

CVE-2020-23593

Disclosure Date: November 23, 2022 (last updated December 22, 2024)
A vulnerability in OPTILINK OP-XT71000N Hardware Version: V2.2, Firmware Version: OP_V3.3.1-191028 allows an unauthenticated, remote attacker to conduct a cross site request forgery (CSRF) attack to enable syslog mode through ' /mgm_log_cfg.asp.' The system starts to log events, 'Remote' mode or 'Both' mode on "Syslog -- Configuration page" logs events and sends to remote syslog server IP and Port.
Attacker Value
Unknown

CVE-2020-23582

Disclosure Date: November 21, 2022 (last updated December 22, 2024)
A vulnerability in the "/admin/wlmultipleap.asp" of optilink OP-XT71000N version: V2.2 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to create Multiple WLAN BSSID.
Attacker Value
Unknown

CVE-2021-27823

Disclosure Date: May 25, 2021 (last updated November 28, 2024)
An information disclosure vulnerability was discovered in /index.class.php (via port 8181) on NetWave System 1.0 which allows unauthenticated attackers to exfiltrate sensitive information from the system.
Attacker Value
Unknown

CVE-2020-5638

Disclosure Date: December 03, 2020 (last updated February 22, 2025)
Cross-site scripting vulnerability in desknet's NEO (desknet's NEO Small License V5.5 R1.5 and earlier, and desknet's NEO Enterprise License V5.5 R1.5 and earlier) allows remote attackers to inject arbitrary script via unspecified vectors.
Attacker Value
Unknown

CVE-2018-16752

Disclosure Date: September 20, 2018 (last updated November 27, 2024)
LINK-NET LW-N605R devices with firmware 12.20.2.1486 allow Remote Code Execution via shell metacharacters in the HOST field of the ping feature at adm/systools.asp. Authentication is needed but the default password of admin for the admin account may be used in some cases.
0
Attacker Value
Unknown

CVE-2018-17051

Disclosure Date: September 14, 2018 (last updated November 27, 2024)
K-Net Cisco Configuration Manager through 2014-11-19 has XSS via devices.php.
0
Attacker Value
Unknown

CVE-2018-0496

Disclosure Date: June 12, 2018 (last updated November 26, 2024)
Directory traversal issues in the D-Mod extractor in DFArc and DFArc2 (as well as in RTsoft's Dink Smallwood HD / ProtonSDK version) before 3.14 allow an attacker to overwrite arbitrary files on the user's system.
0
Attacker Value
Unknown

CVE-2009-2325

Disclosure Date: July 05, 2009 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in Clicknet CMS 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the side parameter.
0