Show filters
222 Total Results
Displaying 101-110 of 222
Sort by:
Attacker Value
Unknown

CVE-2021-22642

Disclosure Date: July 28, 2022 (last updated February 24, 2025)
An attacker could use specially crafted invalid Modbus frames to crash the Ovarro TBox system.
Attacker Value
Unknown

CVE-2021-22640

Disclosure Date: July 28, 2022 (last updated February 24, 2025)
An attacker can decrypt the Ovarro TBox login password by communication capture and brute force attacks.
Attacker Value
Unknown

CVE-2020-21406

Disclosure Date: July 20, 2022 (last updated October 07, 2023)
An issue was discovered in RK Smart TV Box MAX and V88 SmartTV box that allows attackers to cause a denial of service via the switchNextDisplayInterface service.
Attacker Value
Unknown

CVE-2022-32517

Disclosure Date: June 14, 2022 (last updated February 24, 2025)
A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause an adversary to trick the interface user/admin into interacting with the application in an unintended way when the product does not implement restrictions on the ability to render within frames on external addresses. Affected Products: Conext™ ComBox (All Versions)
Attacker Value
Unknown

CVE-2022-32515

Disclosure Date: June 14, 2022 (last updated February 24, 2025)
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause brute force attacks to take over the admin account when the product does not implement a rate limit mechanism on the admin authentication form. Affected Products: Conext™ ComBox (All Versions)
Attacker Value
Unknown

CVE-2022-32516

Disclosure Date: June 14, 2022 (last updated February 24, 2025)
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could cause system’s configurations override and cause a reboot loop when the product suffers from POST-Based Cross-Site Request Forgery (CSRF). Affected Products: Conext™ ComBox (All Versions)
Attacker Value
Unknown

CVE-2022-30065

Disclosure Date: May 18, 2022 (last updated February 23, 2025)
A use-after-free in Busybox 1.35-x's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the copyvar function.
Attacker Value
Unknown

CVE-2021-45878

Disclosure Date: March 21, 2022 (last updated February 23, 2025)
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by incorrect access control. Lack of access control on the web manger pages allows any user to view and modify information.
Attacker Value
Unknown

CVE-2021-45877

Disclosure Date: March 21, 2022 (last updated February 23, 2025)
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by hard coded credentials. A hardcoded credential exist in /etc/tomcat8/tomcat-user.xml, which allows attackers to gain authorized access and control the tomcat completely on port 8000 in the tomcat manger page.
Attacker Value
Unknown

CVE-2021-45876

Disclosure Date: March 21, 2022 (last updated February 23, 2025)
Multiple versions of GARO Wallbox GLB/GTB/GTC are affected by unauthenticated command injection. The url parameter of the function module downloadAndUpdate is vulnerable to an command Injection. Unfiltered user input is used to generate code which then gets executed when downloading new firmware.