Show filters
192 Total Results
Displaying 181-190 of 192
Sort by:
Attacker Value
Unknown
CVE-2021-46353
Disclosure Date: March 04, 2022 (last updated February 23, 2025)
An information disclosure in web interface in D-Link DIR-X1860 before 1.03 RevA1 allows a remote unauthenticated attacker to send a specially crafted HTTP request and gain knowledge of different absolute paths that are being used by the web application.
0
Attacker Value
Unknown
CVE-2021-41445
Disclosure Date: February 10, 2022 (last updated February 23, 2025)
A reflected cross-site-scripting attack in web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to execute code in the device of the victim via sending a specific URL to the unauthenticated victim.
0
Attacker Value
Unknown
CVE-2021-41442
Disclosure Date: February 09, 2022 (last updated February 23, 2025)
An HTTP smuggling attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.
0
Attacker Value
Unknown
CVE-2021-41441
Disclosure Date: February 09, 2022 (last updated February 23, 2025)
A DoS attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to reboot the router via sending a specially crafted URL to an authenticated victim. The authenticated victim need to visit this URL, for the router to reboot.
0
Attacker Value
Unknown
CVE-2021-25810
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end', and 'dest_port' parameters.
0
Attacker Value
Unknown
CVE-2021-25811
Disclosure Date: April 29, 2021 (last updated November 28, 2024)
MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter. Upon subsequent device restarts after this vulnerability is exploted the device will not be able to access the webserver unless the listen_http_lan parameter to uhttpd.json is manually fixed.
0
Attacker Value
Unknown
CVE-2020-14099
Disclosure Date: April 08, 2021 (last updated February 22, 2025)
On Xiaomi router AX1800 rom version < 1.0.336 and RM1800 root version < 1.0.26, the encryption scheme for a user's backup files uses hard-coded keys, which can expose sensitive information such as a user's password.
0
Attacker Value
Unknown
CVE-2020-14102
Disclosure Date: January 13, 2021 (last updated February 22, 2025)
There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.
0
Attacker Value
Unknown
CVE-2020-14101
Disclosure Date: January 13, 2021 (last updated November 28, 2024)
The data collection SDK of the router web management interface caused the leakage of the token. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.
0
Attacker Value
Unknown
CVE-2020-14098
Disclosure Date: January 13, 2021 (last updated February 22, 2025)
The login verification can be bypassed by using the problem that the time is not synchronized after the router restarts. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.
0