Show filters
51 Total Results
Displaying 21-30 of 51
Sort by:
Attacker Value
Unknown

CVE-2015-5536

Disclosure Date: August 13, 2015 (last updated October 05, 2023)
Belkin N300 Dual-Band Wi-Fi Range Extender with firmware before 1.04.10 allows remote authenticated users to execute arbitrary commands via the (1) sub_dir parameter in a formUSBStorage request; pinCode parameter in a (2) formWpsStart or (3) formiNICWpsStart request; (4) wps_enrolee_pin parameter in a formWlanSetupWPS request; or unspecified parameters in a (5) formWlanMP, (6) formBSSetSitesurvey, (7) formHwSet, or (8) formConnectionSetting request.
0
Attacker Value
Unknown

CVE-2014-1635

Disclosure Date: November 12, 2014 (last updated October 05, 2023)
Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote attackers to execute arbitrary code via a long string in the jump parameter.
0
Attacker Value
Unknown

CVE-2013-3092

Disclosure Date: September 29, 2014 (last updated October 05, 2023)
The Belkin N300 (F7D7301v1) router allows remote attackers to bypass authentication and gain privileges via vectors related to incorrect validation of the HTTP Authorization header.
0
Attacker Value
Unknown

CVE-2013-3086

Disclosure Date: September 29, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in util_system.html in Belkin N900 router allows remote attackers to hijack the authentication of administrators for requests that change configuration settings including passwords and remote management ports.
0
Attacker Value
Unknown

CVE-2013-3089

Disclosure Date: September 29, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in apply.cgi in Belkin N300 (F7D7301v1) router allows remote attackers to hijack the authentication of administrators for requests that modify configuration.
0
Attacker Value
Unknown

CVE-2013-3083

Disclosure Date: September 29, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in cgi-bin/system_setting.exe in Belkin F5D8236-4 v2 allows remote attackers to hijack the authentication of administrators for requests that open the remote management interface on arbitrary ports via the remote_mgmt_enabled and remote_mgmt_port parameters.
0
Attacker Value
Unknown

CVE-2014-2962

Disclosure Date: June 19, 2014 (last updated October 05, 2023)
Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.
0
Attacker Value
Unknown

CVE-2013-6948

Disclosure Date: February 22, 2014 (last updated October 05, 2023)
The peerAddresses API in the Belkin WeMo Home Automation firmware before 3949 allows remote attackers to read arbitrary files via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
0
Attacker Value
Unknown

CVE-2013-6951

Disclosure Date: February 22, 2014 (last updated October 05, 2023)
The Belkin WeMo Home Automation firmware before 3949 does not maintain a set of Certification Authority public keys, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary X.509 certificate.
0
Attacker Value
Unknown

CVE-2013-6949

Disclosure Date: February 22, 2014 (last updated October 05, 2023)
The Belkin WeMo Home Automation firmware before 3949 does not properly use the STUN and TURN protocols, which allows remote attackers to hijack connections and possibly have unspecified other impact by leveraging access to a single WeMo device.
0