Show filters
42 Total Results
Displaying 21-30 of 42
Sort by:
Attacker Value
Unknown

CVE-2015-7290

Disclosure Date: November 21, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 allows remote attackers to inject arbitrary web script or HTML via the pwd parameter.
0
Attacker Value
Unknown

CVE-2014-9406

Disclosure Date: December 18, 2014 (last updated October 05, 2023)
ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier has a default password of password for the admin account, which makes it easier for remote attackers to obtain access via a request to home_loggedout.php.
0
Attacker Value
Unknown

CVE-2014-5438

Disclosure Date: December 17, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allows remote authenticated users to inject arbitrary web script or HTML via the computer_name parameter to connected_devices_computers_edit.php.
0
Attacker Value
Unknown

CVE-2014-5437

Disclosure Date: December 17, 2014 (last updated October 05, 2023)
Multiple cross-site request forgery (CSRF) vulnerabilities in ARRIS Touchstone TG862G/CT Telephony Gateway with firmware 7.6.59S.CT and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) enable remote management via a request to remote_management.php, (2) add a port forwarding rule via a request to port_forwarding_add.php, (3) change the wireless network to open via a request to wireless_network_configuration_edit.php, or (4) conduct cross-site scripting (XSS) attacks via the keyword parameter to managed_sites_add_keyword.php.
0
Attacker Value
Unknown

CVE-2014-8425

Disclosure Date: November 28, 2014 (last updated October 05, 2023)
The management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to obtain credentials by reading the configuration files.
0
Attacker Value
Unknown

CVE-2014-8423

Disclosure Date: November 28, 2014 (last updated October 05, 2023)
Unspecified vulnerability in the management portal in ARRIS VAP2500 before FW08.41 allows remote attackers to execute arbitrary commands via unknown vectors.
0
Attacker Value
Unknown

CVE-2014-8424

Disclosure Date: November 28, 2014 (last updated October 05, 2023)
ARRIS VAP2500 before FW08.41 does not properly validate passwords, which allows remote attackers to bypass authentication.
0
Attacker Value
Unknown

CVE-2014-4863

Disclosure Date: September 05, 2014 (last updated October 05, 2023)
The Arris Touchstone DG950A cable modem with software 7.10.131 has an SNMP community of public, which allows remote attackers to obtain sensitive password, key, and SSID information via an SNMP request.
0
Attacker Value
Unknown

CVE-2013-6034

Disclosure Date: February 04, 2014 (last updated October 05, 2023)
The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE-250 and JUE-500; and Thuraya IP satellite terminals has hardcoded credentials, which makes it easier for attackers to obtain unspecified login access via unknown vectors.
0
Attacker Value
Unknown

CVE-2013-6035

Disclosure Date: February 04, 2014 (last updated October 05, 2023)
The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE-250 and JUE-500; and Thuraya IP satellite terminals does not require authentication for sessions on TCP port 1827, which allows remote attackers to execute arbitrary code via unspecified protocol operations.
0