Show filters
28 Total Results
Displaying 21-28 of 28
Sort by:
Attacker Value
Unknown
CVE-2019-3917
Disclosure Date: March 05, 2019 (last updated November 27, 2024)
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 allows a remote, unauthenticated attacker to enable telnetd on the router via a crafted HTTP request.
0
Attacker Value
Unknown
CVE-2019-3922
Disclosure Date: March 05, 2019 (last updated November 27, 2024)
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST request sent by a remote, unauthenticated attacker to /GponForm/fsetup_Form. An attacker can leverage this vulnerability to potentially execute arbitrary code.
0
Attacker Value
Unknown
CVE-2019-3918
Disclosure Date: March 05, 2019 (last updated November 27, 2024)
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 contains multiple hard coded credentials for the Telnet and SSH interfaces.
0
Attacker Value
Unknown
CVE-2019-3921
Disclosure Date: March 05, 2019 (last updated November 27, 2024)
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST request sent by a remote, authenticated attacker to /GponForm/usb_Form?script/. An attacker can leverage this vulnerability to potentially execute arbitrary code.
0
Attacker Value
Unknown
CVE-2019-3919
Disclosure Date: March 05, 2019 (last updated November 27, 2024)
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to command injection via crafted HTTP request sent by a remote, authenticated attacker to /GponForm/usb_restore_Form?script/.
0
Attacker Value
Unknown
CVE-2018-10562
Disclosure Date: May 04, 2018 (last updated January 24, 2025)
An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output.
0
Attacker Value
Unknown
CVE-2018-10561
Disclosure Date: May 04, 2018 (last updated January 24, 2025)
An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.
0
Attacker Value
Unknown
CVE-2015-2055
Disclosure Date: February 23, 2015 (last updated October 05, 2023)
Zhone GPON 2520 with firmware R4.0.2.566b allows remote attackers to cause a denial of service via a long string in the oldpassword parameter.
0