Show filters
37 Total Results
Displaying 1-10 of 37
Sort by:
Attacker Value
Unknown

CVE-2025-1143

Disclosure Date: February 11, 2025 (last updated February 11, 2025)
Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in through the SSH service using these credentials and obtain root privilege of the system.
0
Attacker Value
Unknown

CVE-2025-0681

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
The Cloud MQTT service of the affected products supports wildcard topic subscription which could allow an attacker to obtain sensitive information from tapping the service communications.
0
Attacker Value
Unknown

CVE-2025-0680

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
Affected products contain a vulnerability in the device cloud rpc command handling process that could allow remote attackers to take control over arbitrary devices connected to the cloud.
0
Attacker Value
Unknown

CVE-2024-11983

Disclosure Date: November 29, 2024 (last updated December 21, 2024)
Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject arbitrary system commands into a specific SSH function and execute them on the device.
0
Attacker Value
Unknown

CVE-2024-11982

Disclosure Date: November 29, 2024 (last updated December 21, 2024)
Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers with administrator privileges can access the user settings page to retrieve plaintext passwords.
0
Attacker Value
Unknown

CVE-2024-11981

Disclosure Date: November 29, 2024 (last updated December 21, 2024)
Certain models of routers from Billion Electric has an Authentication Bypass vulnerability, allowing unautheticated attackers to retrive contents of arbitrary web pages.
0
Attacker Value
Unknown

CVE-2024-11980

Disclosure Date: November 29, 2024 (last updated December 21, 2024)
Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device.
0
Attacker Value
Unknown

CVE-2022-42953

Disclosure Date: December 25, 2022 (last updated October 08, 2023)
Certain ZKTeco products (ZEM500-510-560-760, ZEM600-800, ZEM720, ZMM) allow access to sensitive information via direct requests for the form/DataApp?style=1 and form/DataApp?style=0 URLs. The affected versions may be before 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and 15.00 (ZMM200-220-210). The fixed versions are firmware version 8.88 (ZEM500-510-560-760, ZEM600-800, ZEM720) and firmware version 15.00 (ZMM200-220-210).
Attacker Value
Unknown

CVE-2021-34400

Disclosure Date: November 20, 2021 (last updated October 07, 2023)
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed memory, which may lead to information disclosure.
Attacker Value
Unknown

CVE-2021-34399

Disclosure Date: November 20, 2021 (last updated October 07, 2023)
NVIDIA GPU and Tegra hardware contain a vulnerability in the internal microcontroller which may allow a user with elevated privileges to gain access to information from unscrubbed registers, which may lead to information disclosure.