Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown
CVE-2024-32850
Disclosure Date: May 31, 2024 (last updated February 26, 2025)
Improper neutralization of special elements used in a command ('Command Injection') exists in SkyBridge MB-A100/MB-A110 firmware Ver. 4.2.2 and earlier and SkyBridge BASIC MB-A130 firmware Ver. 1.5.5 and earlier. If the remote monitoring and control function is enabled on the product, an attacker with access to the product may execute an arbitrary command or login to the product with the administrator privilege.
0
Attacker Value
Unknown
CVE-2024-32850
Disclosure Date: May 31, 2024 (last updated February 26, 2025)
Improper neutralization of special elements used in a command ('Command Injection') exists in SkyBridge MB-A100/MB-A110 firmware Ver. 4.2.2 and earlier and SkyBridge BASIC MB-A130 firmware Ver. 1.5.5 and earlier. If the remote monitoring and control function is enabled on the product, an attacker with access to the product may execute an arbitrary command or login to the product with the administrator privilege.
0
Attacker Value
Unknown
CVE-2023-25072
Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Use of weak credentials exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauthenticated attacker to decrypt password for the WebUI of the product.
0
Attacker Value
Unknown
CVE-2023-25070
Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Cleartext transmission of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier. If the telnet connection is enabled, a remote unauthenticated attacker may eavesdrop on or alter the administrator's communication to the product.
0
Attacker Value
Unknown
CVE-2023-24586
Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Cleartext storage of sensitive information exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote authenticated attacker to obtain an APN credential for the product.
0
Attacker Value
Unknown
CVE-2023-23906
Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Missing authentication for critical function exists in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier, which may allow a remote unauthenticated attacker to execute some critical functions without authentication, e.g., rebooting the product.
0
Attacker Value
Unknown
CVE-2023-22361
Disclosure Date: May 10, 2023 (last updated October 08, 2023)
Improper privilege management vulnerability in SkyBridge MB-A100/110 firmware Ver. 4.2.0 and earlier allows a remote authenticated attacker to alter a WebUI password of the product.
0
Attacker Value
Unknown
CVE-2022-36558
Disclosure Date: August 29, 2022 (last updated February 24, 2025)
Seiko SkyBridge MB-A100/A110 v4.2.0 and below implements a hard-coded passcode for the root account. Attackers are able to access the passcord via the file /etc/ciel.cfg.
0
Attacker Value
Unknown
CVE-2022-36557
Disclosure Date: August 29, 2022 (last updated February 24, 2025)
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain an arbitrary file upload vulnerability via the restore backup function. This vulnerability allows attackers to execute arbitrary code via a crafted html file.
0
Attacker Value
Unknown
CVE-2022-36556
Disclosure Date: August 29, 2022 (last updated February 24, 2025)
Seiko SkyBridge MB-A100/A110 v4.2.0 and below was discovered to contain a command injection vulnerability via the ipAddress parameter at 07system08execute_ping_01.
0