Show filters
54 Total Results
Displaying 51-54 of 54
Sort by:
Attacker Value
Unknown

CVE-2019-15513

Disclosure Date: August 23, 2019 (last updated November 08, 2023)
An issue was discovered in OpenWrt libuci (aka Library for the Unified Configuration Interface) before 15.05.1 as used on Motorola CX2L MWR04L 1.01 and C1 MWR03 1.01 devices. /tmp/.uci/network locking is mishandled after reception of a long SetWanSettings command, leading to a device hang.
0
Attacker Value
Unknown

CVE-2019-12272

Disclosure Date: May 23, 2019 (last updated November 27, 2024)
In OpenWrt LuCI through 0.10, the endpoints admin/status/realtime/bandwidth_status and admin/status/realtime/wireless_status of the web application are affected by a command injection vulnerability.
0
Attacker Value
Unknown

CVE-2018-19630

Disclosure Date: November 28, 2018 (last updated November 27, 2024)
cgi_handle_request in uhttpd in OpenWrt through 18.06.1 and LEDE through 17.01 has unauthenticated reflected XSS via the URI, as demonstrated by a cgi-bin/?[XSS] URI.
0
Attacker Value
Unknown

CVE-2018-11116

Disclosure Date: June 19, 2018 (last updated November 08, 2023)
OpenWrt mishandles access control in /etc/config/rpcd and the /usr/share/rpcd/acl.d files, which allows remote authenticated users to call arbitrary methods (i.e., achieve ubus access over HTTP) that were only supposed to be accessible to a specific user, as demonstrated by the file, log, and service namespaces, potentially leading to remote Information Disclosure or Code Execution. NOTE: The developer disputes this as a vulnerability, indicating that rpcd functions appropriately
0