Show filters
192 Total Results
Displaying 61-70 of 192
Sort by:
Attacker Value
Unknown
CVE-2024-36258
Disclosure Date: January 14, 2025 (last updated January 15, 2025)
A stack-based buffer overflow vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary code execution. An attacker can send an HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2024-34544
Disclosure Date: January 14, 2025 (last updated January 15, 2025)
A command injection vulnerability exists in the wireless.cgi AddMac() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2024-34166
Disclosure Date: January 14, 2025 (last updated January 15, 2025)
An os command injection vulnerability exists in the touchlist_sync.cgi touchlistsync() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of HTTP requests can lead to arbitrary code execution. An attacker can send an HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2024-21797
Disclosure Date: January 14, 2025 (last updated January 15, 2025)
A command execution vulnerability exists in the adm.cgi set_TR069() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2023-7266
Disclosure Date: December 28, 2024 (last updated January 14, 2025)
Some Huawei home routers have a connection hijacking vulnerability. Successful exploitation of this vulnerability may cause DoS or information leakage.(Vulnerability ID:HWPSIRT-2023-76605)
This vulnerability has been assigned a (CVE)ID:CVE-2023-7266
0
Attacker Value
Unknown
CVE-2023-5407
Disclosure Date: April 17, 2024 (last updated July 09, 2024)
Controller denial of service due to improper handling of a specially crafted message received by the controller.
See Honeywell Security Notification for recommendations on upgrading and versioning.
0
Attacker Value
Unknown
CVE-2023-5392
Disclosure Date: April 11, 2024 (last updated April 25, 2024)
C300 information leak due to an analysis feature which allows extracting more memory over the network than required by the function. Honeywell recommends updating to the most recent version of the product. See Honeywell Security Notification for recommendations on upgrading and versioning.
0
Attacker Value
Unknown
CVE-2023-45317
Disclosure Date: October 26, 2023 (last updated November 08, 2023)
The application interface allows users to perform certain actions via
HTTP requests without performing any validity checks to verify the
requests. This can be exploited to perform certain actions with
administrative privileges if a logged-in user visits a malicious web
site.
0
Attacker Value
Unknown
CVE-2023-45228
Disclosure Date: October 26, 2023 (last updated November 08, 2023)
The application suffers from improper access control when editing users.
A user with read permissions can manipulate users, passwords, and
permissions by sending a single HTTP POST request with modified
parameters.
0
Attacker Value
Unknown
CVE-2023-42769
Disclosure Date: October 26, 2023 (last updated November 08, 2023)
The cookie session ID is of insufficient length and can be exploited by
brute force, which may allow a remote attacker to obtain a valid
session, bypass authentication, and manipulate the transmitter.
0