Show filters
95 Total Results
Displaying 21-30 of 95
Sort by:
Attacker Value
Unknown
CVE-2022-4364
Disclosure Date: December 08, 2022 (last updated October 08, 2023)
A vulnerability classified as critical has been found in Teledyne FLIR AX8 up to 1.46.16. Affected is an unknown function of the file palette.php of the component Web Service Handler. The manipulation of the argument palette leads to command injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-215118 is the identifier assigned to this vulnerability.
0
Attacker Value
Unknown
CVE-2021-41437
Disclosure Date: September 26, 2022 (last updated February 24, 2025)
An HTTP response splitting attack in web application in ASUS RT-AX88U before v3.0.0.4.388.20558 allows an attacker to craft a specific URL that if an authenticated victim visits it, the URL will give access to the cloud storage of the attacker.
0
Attacker Value
Unknown
CVE-2022-37063
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
All FLIR AX8 thermal sensor cameras versions up to and including 1.46.16 are vulnerable to Cross Site Scripting (XSS) due to improper input sanitization. An authenticated remote attacker can execute arbitrary JavaScript code in the web management interface. A successful exploit could allow the attacker to insert malicious JavaScript code.
0
Attacker Value
Unknown
CVE-2022-37062
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
All FLIR AX8 thermal sensor cameras version up to and including 1.46.16 are affected by an insecure design vulnerability due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains the path of the SQLite users database and download it. A successful exploit could allow the attacker to extract usernames and hashed passwords.
0
Attacker Value
Unknown
CVE-2022-37060
Disclosure Date: August 18, 2022 (last updated February 24, 2025)
FLIR AX8 thermal sensor cameras version up to and including 1.46.16 is vulnerable to Directory Traversal due to an improper access restriction. An unauthenticated, remote attacker can exploit this by sending a URI that contains directory traversal characters to disclose the contents of files located outside of the server's restricted path.
0
Attacker Value
Unknown
CVE-2022-26376
Disclosure Date: July 27, 2022 (last updated February 24, 2025)
A memory corruption vulnerability exists in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.. A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2021-43702
Disclosure Date: July 05, 2022 (last updated February 24, 2025)
ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.
0
Attacker Value
Unknown
CVE-2022-26674
Disclosure Date: April 22, 2022 (last updated February 23, 2025)
ASUS RT-AX88U has a Format String vulnerability, which allows an unauthenticated remote attacker to write to arbitrary memory address and perform remote arbitrary code execution, arbitrary system operation or disrupt service.
0
Attacker Value
Unknown
CVE-2022-26673
Disclosure Date: April 22, 2022 (last updated February 23, 2025)
ASUS RT-AX88U has insufficient filtering for special characters in the HTTP header parameter. A remote attacker with general user privilege can exploit this vulnerability to inject JavaScript and perform Stored Cross-Site Scripting (XSS) attacks.
0
Attacker Value
Unknown
CVE-2022-24655
Disclosure Date: March 18, 2022 (last updated February 23, 2025)
A stack overflow vulnerability exists in the upnpd service in Netgear EX6100v1 201.0.2.28, CAX80 2.1.2.6, and DC112A 1.0.0.62, which may lead to the execution of arbitrary code without authentication.
0