Show filters
39 Total Results
Displaying 1-10 of 39
Sort by:
Attacker Value
Unknown
CVE-2023-23560
Disclosure Date: January 23, 2023 (last updated October 08, 2023)
In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.
1
Attacker Value
Unknown
CVE-2024-10119
Disclosure Date: October 18, 2024 (last updated November 02, 2024)
The wireless router WRTM326 from SECOM does not properly validate a specific parameter. An unauthenticated remote attacker could execute arbitrary system commands by sending crafted requests.
0
Attacker Value
Unknown
CVE-2024-6045
Disclosure Date: June 17, 2024 (last updated January 05, 2025)
Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can force the device to enable Telnet service by accessing a specific URL and can log in by using the administrator credentials obtained from analyzing the firmware.
0
Attacker Value
Unknown
CVE-2024-6044
Disclosure Date: June 17, 2024 (last updated January 05, 2025)
Certain models of D-Link wireless routers have a path traversal vulnerability. Unauthenticated attackers on the same local area network can read arbitrary system files by manipulating the URL.
0
Attacker Value
Unknown
CVE-2023-22960
Disclosure Date: January 23, 2023 (last updated October 08, 2023)
Lexmark products through 2023-01-10 have Improper Control of Interaction Frequency.
0
Attacker Value
Unknown
CVE-2021-42553
Disclosure Date: October 21, 2022 (last updated October 08, 2023)
A buffer overflow vulnerability in stm32_mw_usb_host of STMicroelectronics in versions before 3.5.1 allows an attacker to execute arbitrary code when the descriptor contains more endpoints than USBH_MAX_NUM_ENDPOINTS. The library is typically integrated when using a RTOS such as FreeRTOS on STM32 MCUs.
0
Attacker Value
Unknown
CVE-2022-29850
Disclosure Date: August 26, 2022 (last updated October 08, 2023)
Various Lexmark products through 2022-04-27 allow an attacker who has already compromised an affected Lexmark device to maintain persistence across reboots.
0
Attacker Value
Unknown
CVE-2022-2758
Disclosure Date: August 16, 2022 (last updated November 29, 2024)
Passwords are not adequately encrypted during the communication process between all versions of LS Industrial Systems (LSIS) Co. Ltd LS Electric XG5000 software prior to V4.0 and LS Electric PLCs: all versions of XGK-CPUU/H/A/S/E prior to V3.50, all versions of XGI-CPUU/UD/H/S/E prior to V3.20, all versions of XGR-CPUH prior to V1.80, all versions of XGB-XBMS prior to V3.00, all versions of XGB-XBCH prior to V1.90, and all versions of XGB-XECH prior to V1.30. This would allow an attacker to identify and decrypt the password of the affected PLCs by sniffing the PLC’s communication traffic.
0
Attacker Value
Unknown
CVE-2021-44737
Disclosure Date: January 20, 2022 (last updated February 23, 2025)
PJL directory traversal vulnerability in Lexmark devices through 2021-12-07 that can be leveraged to overwrite internal configuration files.
0
Attacker Value
Unknown
CVE-2021-44735
Disclosure Date: January 20, 2022 (last updated February 23, 2025)
Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
0