Show filters
1,006 Total Results
Displaying 71-80 of 1,006
Sort by:
Attacker Value
Unknown

CVE-2023-0246

Disclosure Date: January 12, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, was found in earclink ESPCMS P8.21120101. Affected is an unknown function of the component Content Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-218154 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-0222

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
A CWE-269: Improper Privilege Management vulnerability exists that could cause a denial of service of the Ethernet communication of the controller when sending a specific request over SNMP. Affected products: Modicon M340 CPUs(BMXP34* versions prior to V3.40), Modicon M340 X80 Ethernet Communication modules:BMXNOE0100 (H), BMXNOE0110 (H), BMXNOR0200H RTU(BMXNOE* all versions)(BMXNOR* versions prior to v1.7 IR24)
Attacker Value
Unknown

CVE-2022-37301

Disclosure Date: November 22, 2022 (last updated February 24, 2025)
A CWE-191: Integer Underflow (Wrap or Wraparound) vulnerability exists that could cause a denial of service of the controller due to memory access violations when using the Modbus TCP protocol. Affected products: Modicon M340 CPU (part numbers BMXP34*)(V3.40 and prior), Modicon M580 CPU (part numbers BMEP* and BMEH*)(V3.22 and prior), Legacy Modicon Quantum/Premium(All Versions), Modicon Momentum MDI (171CBU*)(All Versions), Modicon MC80 (BMKC80)(V1.7 and prior)
Attacker Value
Unknown

CVE-2022-44089

Disclosure Date: November 10, 2022 (last updated December 22, 2024)
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.
Attacker Value
Unknown

CVE-2022-44088

Disclosure Date: November 10, 2022 (last updated December 22, 2024)
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.
Attacker Value
Unknown

CVE-2022-44087

Disclosure Date: November 10, 2022 (last updated December 22, 2024)
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component UPFILE_PIC_ZOOM_HIGHT.
Attacker Value
Unknown

CVE-2022-40475

Disclosure Date: September 29, 2022 (last updated February 24, 2025)
TOTOLINK A860R V4.1.2cu.5182_B20201027 was discovered to contain a command injection via the component /cgi-bin/downloadFile.cgi.
Attacker Value
Unknown

CVE-2022-37300

Disclosure Date: September 12, 2022 (last updated February 24, 2025)
A CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability exists that could cause unauthorized access in read and write mode to the controller when communicating over Modbus. Affected Products: EcoStruxure Control Expert Including all Unity Pro versions (former name of EcoStruxure Control Expert) (V15.0 SP1 and prior), EcoStruxure Process Expert, Including all versions of EcoStruxure Hybrid DCS (former name of EcoStruxure Process Expert) (V2021 and prior), Modicon M340 CPU (part numbers BMXP34*) (V3.40 and prior), Modicon M580 CPU (part numbers BMEP* and BMEH*) (V3.20 and prior).
Attacker Value
Unknown

CVE-2022-37843

Disclosure Date: September 06, 2022 (last updated February 24, 2025)
In TOTOLINK A860R V4.1.2cu.5182_B20201027 in cstecgi.cgi, the acquired parameters are directly put into the system for execution without filtering, resulting in a command injection vulnerability.
Attacker Value
Unknown

CVE-2022-37842

Disclosure Date: September 06, 2022 (last updated February 24, 2025)
In TOTOLINK A860R V4.1.2cu.5182_B20201027, the parameters in infostat.cgi are not filtered, causing a buffer overflow vulnerability.