Show filters
192 Total Results
Displaying 61-70 of 192
Sort by:
Attacker Value
Unknown

CVE-2024-36258

Disclosure Date: January 14, 2025 (last updated January 15, 2025)
A stack-based buffer overflow vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send an HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown

CVE-2024-34544

Disclosure Date: January 14, 2025 (last updated January 15, 2025)
A command injection vulnerability exists in the wireless.cgi AddMac() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown

CVE-2024-34166

Disclosure Date: January 14, 2025 (last updated January 15, 2025)
An os command injection vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of HTTP requests can lead to arbitrary code execution. An attacker can send an HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown

CVE-2024-21797

Disclosure Date: January 14, 2025 (last updated January 15, 2025)
A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown

CVE-2023-7266

Disclosure Date: December 28, 2024 (last updated January 14, 2025)
Some Huawei home routers have a connection hijacking vulnerability. Successful exploitation of this vulnerability may cause DoS or information leakage.(Vulnerability ID:HWPSIRT-2023-76605) This vulnerability has been assigned a (CVE)ID:CVE-2023-7266
Attacker Value
Unknown

CVE-2023-5407

Disclosure Date: April 17, 2024 (last updated July 09, 2024)
Controller denial of service due to improper handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning.
0
Attacker Value
Unknown

CVE-2023-5392

Disclosure Date: April 11, 2024 (last updated April 25, 2024)
C300 information leak due to an analysis feature which allows extracting more memory over the network than required by the function. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.
0
Attacker Value
Unknown

CVE-2023-45317

Disclosure Date: October 26, 2023 (last updated November 08, 2023)
The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
Attacker Value
Unknown

CVE-2023-45228

Disclosure Date: October 26, 2023 (last updated November 08, 2023)
The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with modified parameters.
Attacker Value
Unknown

CVE-2023-42769

Disclosure Date: October 26, 2023 (last updated November 08, 2023)
The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.