Show filters
55 Total Results
Displaying 41-50 of 55
Sort by:
Attacker Value
Unknown

CVE-2021-21729

Disclosure Date: April 13, 2021 (last updated February 22, 2025)
Some ZTE products have CSRF vulnerability. Because some pages lack CSRF random value verification, attackers could perform illegal authorization operations by constructing messages.This affects: ZXHN H168N V3.5.0_EG1T5_TE, V2.5.5, ZXHN H108N V2.5.5_BTMT1
Attacker Value
Unknown

CVE-2020-27282

Disclosure Date: March 15, 2021 (last updated February 22, 2025)
In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an XML validation vulnerability in the ventilator allows privileged attackers with physical access to render the device persistently unusable by uploading specially crafted configuration files.
Attacker Value
Unknown

CVE-2020-27290

Disclosure Date: March 15, 2021 (last updated February 22, 2025)
In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an information disclosure vulnerability in the ventilator allows attackers with physical access to the configuration interface's logs to get valid checksums for tampered configuration files.
Attacker Value
Unknown

CVE-2020-27278

Disclosure Date: March 15, 2021 (last updated February 22, 2025)
In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, hard-coded credentials in the ventilator allow attackers with physical access to obtain admin privileges for the device’s configuration interface.
Attacker Value
Unknown

CVE-2020-6877

Disclosure Date: November 05, 2020 (last updated November 28, 2024)
A ZTE product is impacted by an information leak vulnerability. An attacker could use this vulnerability to obtain the authentication password of the handheld terminal and access the device illegally for operation. This affects: ZXA10 eODN V2.3P2T1
Attacker Value
Unknown

CVE-2019-19743

Disclosure Date: December 16, 2019 (last updated November 27, 2024)
On D-Link DIR-615 devices, a normal user is able to create a root(admin) user from the D-Link portal.
Attacker Value
Unknown

CVE-2019-6725

Disclosure Date: May 31, 2019 (last updated November 27, 2024)
The rpWLANRedirect.asp ASP page is accessible without authentication on ZyXEL P-660HN-T1 V2 (2.00(AAKK.3)) devices. After accessing the page, the admin user's password can be obtained by viewing the HTML source code, and the interface of the modem can be accessed as admin.
0
Attacker Value
Unknown

CVE-2019-1649

Disclosure Date: May 14, 2019 (last updated November 27, 2024)
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based Secure Boot functionality. The vulnerability is due to an improper check on the area of code that manages on-premise updates to a Field Programmable Gate Array (FPGA) part of the Secure Boot hardware implementation. An attacker with elevated privileges and access to the underlying operating system that is running on the affected device could exploit this vulnerability by writing a modified firmware image to the FPGA. A successful exploit could either cause the device to become unusable (and require a hardware replacement) or allow tampering with the Secure Boot verification process, which under some circumstances may allow the attacker to install and boot a malicious softw…
Attacker Value
Unknown

CVE-2018-10110

Disclosure Date: April 18, 2018 (last updated November 26, 2024)
D-Link DIR-615 T1 devices allow XSS via the Add User feature.
0
Attacker Value
Unknown

CVE-2014-2359

Disclosure Date: April 06, 2018 (last updated November 26, 2024)
OleumTech Wireless Sensor Network devices allow remote attackers to obtain sensitive information about sensor nodes or spoof devices by reading cleartext protocol data.
0