Show filters
37 Total Results
Displaying 1-10 of 37
Sort by:
Attacker Value
Unknown
CVE-2024-8105
Disclosure Date: August 26, 2024 (last updated August 27, 2024)
A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.
0
Attacker Value
Unknown
CVE-2024-6045
Disclosure Date: June 17, 2024 (last updated January 05, 2025)
Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can force the device to enable Telnet service by accessing a specific URL and can log in by using the administrator credentials obtained from analyzing the firmware.
0
Attacker Value
Unknown
CVE-2024-6044
Disclosure Date: June 17, 2024 (last updated January 05, 2025)
Certain models of D-Link wireless routers have a path traversal vulnerability. Unauthenticated attackers on the same local area network can read arbitrary system files by manipulating the URL.
0
Attacker Value
Unknown
CVE-2023-7220
Disclosure Date: January 09, 2024 (last updated January 13, 2024)
A vulnerability was found in Totolink NR1800X 9.1.0u.6279_B20210910 and classified as critical. Affected by this issue is the function loginAuth of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument password leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-249854 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-49701
Disclosure Date: November 30, 2023 (last updated December 06, 2023)
Memory Corruption in SIM management while USIMPhase2init
0
Attacker Value
Unknown
CVE-2023-49700
Disclosure Date: November 30, 2023 (last updated December 06, 2023)
Security best practices violations, a string operation in Streamingmedia will write past the end of fixed-size destination buffer if the source buffer is too large.
0
Attacker Value
Unknown
CVE-2023-49699
Disclosure Date: November 30, 2023 (last updated December 06, 2023)
Memory Corruption in IMS while calling VoLTE Streamingmedia Interface
0
Attacker Value
Unknown
CVE-2023-36340
Disclosure Date: October 16, 2023 (last updated October 19, 2023)
TOTOLINK NR1800X V9.1.0u.6279_B20210910 was discovered to contain a stack overflow via the http_host parameter in the function loginAuth.
0
Attacker Value
Unknown
CVE-2022-44256
Disclosure Date: November 23, 2022 (last updated October 08, 2023)
TOTOLINK LR350 V9.3.5u.6369_B20220309 contains a post-authentication buffer overflow via parameter lang in the setLanguageCfg function.
0
Attacker Value
Unknown
CVE-2022-28866
Disclosure Date: October 12, 2022 (last updated October 08, 2023)
Multiple Improper Access Control was discovered in Nokia AirFrame BMC Web GUI < R18 Firmware v4.13.00. It does not properly validate requests for access to (or editing of) data and functionality in all endpoints under /#settings/* and /api/settings/*. By not verifying the permissions for access to resources, it allows a potential attacker to view pages, with sensitive data, that are not allowed, and modify system configurations also causing DoS, which should be accessed only by user with administration profile, bypassing all controls (without checking for user identity).
0