Show filters
192 Total Results
Displaying 61-70 of 192
Sort by:
Attacker Value
Unknown

CVE-2023-51954

Disclosure Date: January 10, 2024 (last updated January 13, 2024)
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.port parameter in the function formSetIptv.
Attacker Value
Unknown

CVE-2023-51953

Disclosure Date: January 10, 2024 (last updated January 13, 2024)
Tenda AX1803 v1.0.0.1 contains a stack overflow via the iptv.stb.mode parameter in the function formSetIptv.
Attacker Value
Unknown

CVE-2023-51952

Disclosure Date: January 10, 2024 (last updated January 13, 2024)
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function formSetIptv.
Attacker Value
Unknown

CVE-2023-51966

Disclosure Date: January 10, 2024 (last updated January 13, 2024)
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function setIptvInfo.
Attacker Value
Unknown

CVE-2023-51961

Disclosure Date: January 10, 2024 (last updated January 13, 2024)
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stballvlans parameter in the function formGetIptv.
Attacker Value
Unknown

CVE-2023-51972

Disclosure Date: January 10, 2024 (last updated January 13, 2024)
Tenda AX1803 v1.0.0.1 was discovered to contain a command injection vulnerability via the function fromAdvSetLanIp.
Attacker Value
Unknown

CVE-2023-51971

Disclosure Date: January 10, 2024 (last updated January 13, 2024)
Tenda AX1803 v1.0.0.1 contains a stack overflow via the adv.iptv.stbpvid parameter in the function getIptvInfo.
Attacker Value
Unknown

CVE-2023-50921

Disclosure Date: January 03, 2024 (last updated January 11, 2024)
An issue was discovered on GL.iNet devices through 4.5.0. Attackers can invoke the add_user interface in the system module to gain root privileges. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.
Attacker Value
Unknown

CVE-2023-50922

Disclosure Date: January 03, 2024 (last updated January 11, 2024)
An issue was discovered on GL.iNet devices through 4.5.0. Attackers who are able to steal the AdminToken cookie can execute arbitrary code by uploading a crontab-formatted file to a specific directory and waiting for its execution. This affects A1300 4.4.6, AX1800 4.4.6, AXT1800 4.4.6, MT3000 4.4.6, MT2500 4.4.6, MT6000 4.5.0, MT1300 4.3.7, MT300N-V2 4.3.7, AR750S 4.3.7, AR750 4.3.7, AR300M 4.3.7, and B1300 4.3.7.
Attacker Value
Unknown

CVE-2023-51022

Disclosure Date: December 22, 2023 (last updated December 28, 2023)
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘langFlag’ parameter of the setLanguageCfg interface of the cstecgi .cgi.