Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2024-5560
Disclosure Date: June 12, 2024 (last updated July 26, 2024)
CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the
device’s web interface when an attacker sends a specially crafted HTTP request.
0
Attacker Value
Unknown
CVE-2024-37040
Disclosure Date: June 12, 2024 (last updated July 26, 2024)
CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability
exists that could allow a user with access to the device’s web interface to cause a fault on the
device when sending a malformed HTTP request.
0
Attacker Value
Unknown
CVE-2024-37039
Disclosure Date: June 12, 2024 (last updated July 26, 2024)
CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the
device when an attacker sends a specially crafted HTTP request.
0
Attacker Value
Unknown
CVE-2024-37038
Disclosure Date: June 12, 2024 (last updated July 26, 2024)
CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated
user with access to the device’s web interface to perform unauthorized file and firmware
uploads when crafting custom web requests.
0
Attacker Value
Unknown
CVE-2024-37037
Disclosure Date: June 12, 2024 (last updated July 26, 2024)
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path
Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s
web interface to corrupt files and impact device functionality when sending a crafted HTTP
request.
0
Attacker Value
Unknown
CVE-2024-37036
Disclosure Date: June 12, 2024 (last updated August 15, 2024)
CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass
when sending a malformed POST request and particular configuration parameters are set.
0