Show filters
322 Total Results
Displaying 21-30 of 322
Sort by:
Attacker Value
Unknown
CVE-2023-26319
Disclosure Date: October 11, 2023 (last updated October 17, 2023)
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Xiaomi Xiaomi Router allows Command Injection.
0
Attacker Value
Unknown
CVE-2023-26318
Disclosure Date: October 11, 2023 (last updated October 17, 2023)
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Xiaomi Xiaomi Router allows Overflow Buffers.
0
Attacker Value
Unknown
CVE-2023-3569
Disclosure Date: August 08, 2023 (last updated October 08, 2023)
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file which causes a denial-of-service.
0
Attacker Value
Unknown
CVE-2023-3526
Disclosure Date: August 08, 2023 (last updated October 08, 2023)
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context of the user's browser.
0
Attacker Value
Unknown
CVE-2023-26317
Disclosure Date: August 02, 2023 (last updated October 08, 2024)
Xiaomi routers have an external interface that can lead to command injection. The vulnerability is caused by lax filtering of responses from external interfaces. Attackers can exploit this vulnerability to gain access to the router by hijacking the ISP or upper-layer routing.
0
Attacker Value
Unknown
CVE-2023-31998
Disclosure Date: July 18, 2023 (last updated October 08, 2023)
A heap overflow vulnerability found in EdgeRouters and Aircubes allows a malicious actor to interrupt UPnP service to said devices.
0
Attacker Value
Unknown
CVE-2023-33276
Disclosure Date: June 30, 2023 (last updated October 08, 2023)
The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 responds with a "404 - Not Found" status code if a path is accessed that does not exist. However, the value of the path is reflected in the response. As the application will reflect the supplied path without context-sensitive HTML encoding, it is vulnerable to reflective cross-site scripting (XSS).
0
Attacker Value
Unknown
CVE-2023-33277
Disclosure Date: June 29, 2023 (last updated October 08, 2023)
The web interface of Gira Giersiepen Gira KNX/IP-Router 3.1.3683.0 and 3.3.8.0 allows a remote attacker to read sensitive files via directory-traversal sequences in the URL.
0
Attacker Value
Unknown
CVE-2023-31475
Disclosure Date: May 11, 2023 (last updated October 08, 2023)
An issue was discovered on GL.iNet devices before 3.216. The function guci2_get() found in libglutil.so has a buffer overflow when an item is requested from a UCI context, and the value is pasted into a char pointer to a buffer without checking the size of the buffer.
0
Attacker Value
Unknown
CVE-2023-31473
Disclosure Date: May 11, 2023 (last updated October 08, 2023)
An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. Through the software installation feature, it is possible to inject arbitrary parameters in a request to cause opkg to read an arbitrary file name while using root privileges. The -f option can be used with a configuration file.
0