Show filters
39 Total Results
Displaying 31-39 of 39
Sort by:
Attacker Value
Unknown
CVE-2022-44211
Disclosure Date: December 01, 2022 (last updated October 08, 2023)
In GL.iNet Goodcloud 1.1 Incorrect access control allows a remote attacker to access/change devices' settings.
0
Attacker Value
Unknown
CVE-2022-42054
Disclosure Date: October 27, 2022 (last updated December 22, 2024)
Multiple stored cross-site scripting (XSS) vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 allow attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Company Name and Description text fields.
0
Attacker Value
Unknown
CVE-2022-42055
Disclosure Date: October 27, 2022 (last updated December 22, 2024)
Multiple command injection vulnerabilities in GL.iNet GoodCloud IoT Device Management System Version 1.00.220412.00 via the ping and traceroute tools allow attackers to read arbitrary files on the system.
0
Attacker Value
Unknown
CVE-2022-31898
Disclosure Date: October 27, 2022 (last updated December 22, 2024)
gl-inet GL-MT300N-V2 Mango v3.212 and GL-AX1800 Flint v3.214 were discovered to contain multiple command injection vulnerabilities via the ping_addr and trace_addr function parameters.
0
Attacker Value
Unknown
CVE-2021-44148
Disclosure Date: December 07, 2021 (last updated February 23, 2025)
GL.iNet GL-AR150 2.x before 3.x devices, configured as repeaters, allow cgi-bin/router_cgi?action=scanwifi XSS when an attacker creates an SSID with an XSS payload as the name.
0
Attacker Value
Unknown
CVE-2019-6275
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
Command injection vulnerability in firmware_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2019-6272
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
Command injection vulnerability in login_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2019-6274
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
Directory traversal vulnerability in storage_cgi in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to have unspecified impact via directory traversal sequences.
0
Attacker Value
Unknown
CVE-2019-6273
Disclosure Date: March 21, 2019 (last updated November 27, 2024)
download_file in GL.iNet GL-AR300M-Lite devices with firmware 2.27 allows remote attackers to download arbitrary files.
0