Show filters
26 Total Results
Displaying 11-20 of 26
Sort by:
Attacker Value
Unknown
CVE-2021-30228
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
The api/ZRAndlink/set_ZRAndlink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the iandlink_proc_enable parameter.
0
Attacker Value
Unknown
CVE-2021-30231
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
The api/zrDm/set_ZRElink interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the bssaddr, abiaddr, devtoken, devid, elinksync, or elink_proc_enable parameter.
0
Attacker Value
Unknown
CVE-2021-30230
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
The api/ZRFirmware/set_time_zone interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the zonename parameter.
0
Attacker Value
Unknown
CVE-2021-30229
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
The api/zrDm/set_zrDm interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the dm_enable, AppKey, or Pwd parameter.
0
Attacker Value
Unknown
CVE-2021-30232
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
The api/ZRIGMP/set_IGMP_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the IGMP_PROXY_WAN_CONNECT parameter.
0
Attacker Value
Unknown
CVE-2021-30233
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
The api/ZRIptv/setIptvInfo interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the iptv_vlan parameter.
0
Attacker Value
Unknown
CVE-2021-25812
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
Command injection vulnerability in China Mobile An Lianbao WF-1 1.01 via the 'ip' parameter with a POST request to /api/ZRQos/set_online_client.
0
Attacker Value
Unknown
CVE-2021-30234
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
The api/ZRIGMP/set_MLD_PROXY interface in China Mobile An Lianbao WF-1 router 1.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the MLD_PROXY_WAN_CONNECT parameter.
0
Attacker Value
Unknown
CVE-2021-21304
Disclosure Date: February 08, 2021 (last updated February 22, 2025)
Dynamoose is an open-source modeling tool for Amazon's DynamoDB. In Dynamoose from version 2.0.0 and before version 2.7.0 there was a prototype pollution vulnerability in the internal utility method "lib/utils/object/set.ts". This method is used throughout the codebase for various operations throughout Dynamoose. We have not seen any evidence of this vulnerability being exploited. There is no evidence this vulnerability impacts versions 1.x.x since the vulnerable method was added as part of the v2 rewrite. This vulnerability also impacts v2.x.x beta/alpha versions. Version 2.7.0 includes a patch for this vulnerability.
0
Attacker Value
Unknown
CVE-2019-1010136
Disclosure Date: July 19, 2019 (last updated November 27, 2024)
ChinaMobile GPN2.4P21-C-CN W2001EN-00 is affected by: Incorrect Access Control - Unauthenticated Remote Reboot. The impact is: PLC Wireless Router's are vulnerable to an unauthenticated remote reboot due. The component is: Reboot settings are available to unauthenticated users instead of only authenticaed users. The attack vector is: Remote.
0