Show filters
192 Total Results
Displaying 61-70 of 192
Sort by:
Attacker Value
Unknown
CVE-2023-51954
Disclosure Date: January 10, 2024 (last updated January 13, 2024)
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.
0
Attacker Value
Unknown
CVE-2023-51953
Disclosure Date: January 10, 2024 (last updated January 13, 2024)
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.
0
Attacker Value
Unknown
CVE-2023-51952
Disclosure Date: January 10, 2024 (last updated January 13, 2024)
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.
0
Attacker Value
Unknown
CVE-2023-51966
Disclosure Date: January 10, 2024 (last updated January 13, 2024)
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.
0
Attacker Value
Unknown
CVE-2023-51961
Disclosure Date: January 10, 2024 (last updated January 13, 2024)
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.
0
Attacker Value
Unknown
CVE-2023-51972
Disclosure Date: January 10, 2024 (last updated January 13, 2024)
Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp.
0
Attacker Value
Unknown
CVE-2023-51971
Disclosure Date: January 10, 2024 (last updated January 13, 2024)
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function getIptvInfo.
0
Attacker Value
Unknown
CVE-2023-50921
Disclosure Date: January 03, 2024 (last updated January 11, 2024)
An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.
0
Attacker Value
Unknown
CVE-2023-50922
Disclosure Date: January 03, 2024 (last updated January 11, 2024)
An issue was discovered on GL.iNet devices through 4.5.0. Attackers who are able to steal the AdminToken cookie can execute arbitrary code by uploading a crontab-formatted file to a specific directory and waiting for its execution. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.
0
Attacker Value
Unknown
CVE-2023-51022
Disclosure Date: December 22, 2023 (last updated December 28, 2023)
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langFlag’ parameter of the setLanguageCfg interface of the cstecgi .cgi.
0