Show filters
95 Total Results
Displaying 21-30 of 95
Sort by:
Attacker Value
Unknown

CVE-2022-4364

Disclosure Date: December 08, 2022 (last updated October 08, 2023)
A vulnerability classified as critical has been found in Teledyne FLIR AX8 up to 1.46.16. Affected is an unknown function of the file palette.php of the component Web Service Handler. The manipulation of the argument palette leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-215118 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2021-41437

Disclosure Date: September 26, 2022 (last updated February 24, 2025)
An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the attacker.
Attacker Value
Unknown

CVE-2022-37063

Disclosure Date: August 18, 2022 (last updated February 24, 2025)
All FLIR AX8 thermal sensor cameras versions up to and including 1.46.16 are vulnerable to Cross Site Scripting (XSS) due to improper input sanitization. An authenticated remote attacker can execute arbitrary JavaScript code in the web management interface. A successful exploit could allow the attacker to insert malicious JavaScript code.
Attacker Value
Unknown

CVE-2022-37062

Disclosure Date: August 18, 2022 (last updated February 24, 2025)
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an insecure design vulnerability due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains the path of the SQLite users database and download it. A successful exploit could allow the attacker to extract usernames and hashed passwords.
Attacker Value
Unknown

CVE-2022-37060

Disclosure Date: August 18, 2022 (last updated February 24, 2025)
FLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory Traversal due to an improper access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains directory traversal characters to disclose the contents of files located outside of the server's restricted path.
Attacker Value
Unknown

CVE-2022-26376

Disclosure Date: July 27, 2022 (last updated February 24, 2025)
A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2021-43702

Disclosure Date: July 05, 2022 (last updated February 24, 2025)
ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.
Attacker Value
Unknown

CVE-2022-26674

Disclosure Date: April 22, 2022 (last updated February 23, 2025)
ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remote arbitrary code execution, arbitrary system operation or disrupt service.
0
Attacker Value
Unknown

CVE-2022-26673

Disclosure Date: April 22, 2022 (last updated February 23, 2025)
ASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform Stored Cross-Site Scripting (XSS) attacks.
0
Attacker Value
Unknown

CVE-2022-24655

Disclosure Date: March 18, 2022 (last updated February 23, 2025)
A stack overflow vulnerability exists in the upnpd service in Netgear EX6100v1 201.0.2.28, CAX80 2.1.2.6, and DC112A 1.0.0.62, which may lead to the execution of arbitrary code without authentication.