Show filters
303 Total Results
Displaying 241-250 of 303
Sort by:
Attacker Value
Unknown

CVE-2015-5989

Disclosure Date: December 31, 2015 (last updated November 25, 2024)
Belkin F9K1102 2 devices with firmware 2.10.17 rely on client-side JavaScript code for authorization, which allows remote attackers to obtain administrative privileges via certain changes to LockStatus and Login_Success values.
0
Attacker Value
Unknown

CVE-2015-5987

Disclosure Date: December 31, 2015 (last updated November 25, 2024)
Belkin F9K1102 2 devices with firmware 2.10.17 use an improper algorithm for selecting the ID value in the header of a DNS query, which makes it easier for remote attackers to spoof responses by predicting this value.
0
Attacker Value
Unknown

CVE-2015-5988

Disclosure Date: December 31, 2015 (last updated November 25, 2024)
The web management interface on Belkin F9K1102 2 devices with firmware 2.10.17 has a blank password, which allows remote attackers to obtain administrative privileges by leveraging a LAN session.
0
Attacker Value
Unknown

CVE-2015-5990

Disclosure Date: December 31, 2015 (last updated November 25, 2024)
Cross-site request forgery (CSRF) vulnerability on Belkin F9K1102 2 devices with firmware 2.10.17 allows remote attackers to hijack the authentication of arbitrary users.
0
Attacker Value
Unknown

CVE-2015-6017

Disclosure Date: December 31, 2015 (last updated November 25, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in Forms/rpAuth_1 on ZyXEL P-660HW-T1 2 devices with ZyNOS firmware 3.40(AXH.0) allow remote attackers to inject arbitrary web script or HTML via the (1) LoginPassword or (2) hiddenPassword parameter.
0
Attacker Value
Unknown

CVE-2015-6019

Disclosure Date: December 31, 2015 (last updated November 25, 2024)
The management portal on ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 does not terminate sessions upon a logout action, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.
0
Attacker Value
Unknown

CVE-2015-7283

Disclosure Date: December 31, 2015 (last updated November 25, 2024)
The web administration interface on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 has a default password of 1234 for the admin account, which allows remote attackers to obtain administrative privileges by leveraging a LAN session.
0
Attacker Value
Unknown

CVE-2015-6020

Disclosure Date: December 31, 2015 (last updated November 25, 2024)
ZyXEL PMG5318-B20A devices with firmware 1.00AANC0b5 allow remote authenticated users to obtain administrative privileges by leveraging access to the user account.
0
Attacker Value
Unknown

CVE-2015-7284

Disclosure Date: December 31, 2015 (last updated November 25, 2024)
Cross-site request forgery (CSRF) vulnerability on ZyXEL NBG-418N devices with firmware 1.00(AADZ.3)C0 allows remote attackers to hijack the authentication of arbitrary users.
0
Attacker Value
Unknown

CVE-2015-6018

Disclosure Date: December 31, 2015 (last updated November 25, 2024)
The diagnostic-ping implementation on ZyXEL PMG5318-B20A devices with firmware before 1.00(AANC.2)C0 allows remote attackers to execute arbitrary commands via the PingIPAddr parameter.
0