Show filters
54 Total Results
Displaying 31-40 of 54
Sort by:
Attacker Value
Unknown

CVE-2022-44354

Disclosure Date: November 29, 2022 (last updated October 08, 2023)
SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file.
Attacker Value
Unknown

CVE-2022-40881

Disclosure Date: November 17, 2022 (last updated December 22, 2024)
SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php
Attacker Value
Unknown

CVE-2022-36159

Disclosure Date: September 26, 2022 (last updated October 08, 2023)
Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN Manager interface and open the telnet port then sniff the traffic or inject any malware.
Attacker Value
Unknown

CVE-2022-36158

Disclosure Date: September 26, 2022 (last updated October 08, 2023)
Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious actors to execute Linux commands with root privilege via a hidden web page (/usr/www/ja/mnt_cmd.cgi).
Attacker Value
Unknown

CVE-2022-38100

Disclosure Date: September 01, 2022 (last updated October 08, 2023)
The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with network access can remotely issue a specially formatted UDP request that will cause the entire device to crash and require a physical reboot. A UDP broadcast request could be sent that causes a mass denial-of-service attack on all CME8000 devices connected to the same network.
Attacker Value
Unknown

CVE-2022-3027

Disclosure Date: September 01, 2022 (last updated October 08, 2023)
The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could create an SSID with a malicious name, including non-standard characters that, when the device attempts connecting to the malicious SSID, the device can be exploited to write arbitrary files or display incorrect information.
Attacker Value
Unknown

CVE-2022-36385

Disclosure Date: September 01, 2022 (last updated October 08, 2023)
A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resulting in permanent changes to device functionality. No authentication or controls are in place to prevent a threat actor from maliciously modifying firmware and performing a drive-by attack to load the firmware on any CMS8000 device.
Attacker Value
Unknown

CVE-2022-38453

Disclosure Date: September 01, 2022 (last updated October 08, 2023)
Multiple binary application files on the CMS8000 device are compiled with 'not stripped' and 'debug_info' compilation settings. These compiler settings greatly decrease the level of effort for a threat actor to reverse engineer sensitive code and identify additional vulnerabilities.
Attacker Value
Unknown

CVE-2022-38069

Disclosure Date: September 01, 2022 (last updated October 08, 2023)
Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with momentary physical access to gain privileged access to any device. Privileged credential access enables the extraction of sensitive patient information or modification of device parameters
Attacker Value
Unknown

CVE-2022-35239

Disclosure Date: August 16, 2022 (last updated October 08, 2023)
The image file management page of SolarView Compact SV-CPT-MC310 Ver.7.23 and earlier, and SV-CPT-MC310F Ver.7.23 and earlier contains an insufficient verification vulnerability when uploading files. If this vulnerability is exploited, arbitrary PHP code may be executed if a remote authenticated attacker uploads a specially crafted PHP file.