Show filters
192 Total Results
Displaying 181-190 of 192
Sort by:
Attacker Value
Unknown

CVE-2021-46353

Disclosure Date: March 04, 2022 (last updated February 23, 2025)
An information disclosure in web interface in D-Link DIR-X1860 before 1.03 RevA1 allows a remote unauthenticated attacker to send a specially crafted HTTP request and gain knowledge of different absolute paths that are being used by the web application.
Attacker Value
Unknown

CVE-2021-41445

Disclosure Date: February 10, 2022 (last updated February 23, 2025)
A reflected cross-site-scripting attack in web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to execute code in the device of the victim via sending a specific URL to the unauthenticated victim.
Attacker Value
Unknown

CVE-2021-41442

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
An HTTP smuggling attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.
Attacker Value
Unknown

CVE-2021-41441

Disclosure Date: February 09, 2022 (last updated February 23, 2025)
A DoS attack in the web application of D-Link DIR-X1860 before v1.10WWB09_Beta allows a remote unauthenticated attacker to reboot the router via sending a specially crafted URL to an authenticated victim. The authenticated victim need to visit this URL, for the router to reboot.
Attacker Value
Unknown

CVE-2021-25810

Disclosure Date: April 29, 2021 (last updated February 22, 2025)
Cross site Scripting (XSS) vulnerability in MERCUSYS Mercury X18G 1.0.5 devices, via crafted values to the 'src_dport_start', 'src_dport_end', and 'dest_port' parameters.
Attacker Value
Unknown

CVE-2021-25811

Disclosure Date: April 29, 2021 (last updated November 28, 2024)
MERCUSYS Mercury X18G 1.0.5 devices allow Denial of service via a crafted value to the POST listen_http_lan parameter. Upon subsequent device restarts after this vulnerability is exploted the device will not be able to access the webserver unless the listen_http_lan parameter to uhttpd.json is manually fixed.
Attacker Value
Unknown

CVE-2020-14099

Disclosure Date: April 08, 2021 (last updated February 22, 2025)
On Xiaomi router AX1800 rom version < 1.0.336 and RM1800 root version < 1.0.26, the encryption scheme for a user's backup files uses hard-coded keys, which can expose sensitive information such as a user's password.
Attacker Value
Unknown

CVE-2020-14102

Disclosure Date: January 13, 2021 (last updated February 22, 2025)
There is command injection when ddns processes the hostname, which causes the administrator user to obtain the root privilege of the router. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.
Attacker Value
Unknown

CVE-2020-14101

Disclosure Date: January 13, 2021 (last updated November 28, 2024)
The data collection SDK of the router web management interface caused the leakage of the token. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.
Attacker Value
Unknown

CVE-2020-14098

Disclosure Date: January 13, 2021 (last updated February 22, 2025)
The login verification can be bypassed by using the problem that the time is not synchronized after the router restarts. This affects Xiaomi router AX1800rom version < 1.0.336 and Xiaomi route RM1800 root version < 1.0.26.