Show filters
17 Total Results
Displaying 1-10 of 17
Sort by:
Attacker Value
Unknown
CVE-2025-1143
Disclosure Date: February 11, 2025 (last updated February 11, 2025)
Certain models of routers from Billion Electric has hard-coded embedded linux credentials, allowing attackers to log in through the SSH service using these credentials and obtain root privilege of the system.
0
Attacker Value
Unknown
CVE-2024-11983
Disclosure Date: November 29, 2024 (last updated December 21, 2024)
Certain models of routers from Billion Electric has an OS Command Injection vulnerability, allowing remote attackers with administrator privileges to inject arbitrary system commands into a specific SSH function and execute them on the device.
0
Attacker Value
Unknown
CVE-2024-11982
Disclosure Date: November 29, 2024 (last updated December 21, 2024)
Certain models of routers from Billion Electric has a Plaintext Storage of a Password vulnerability. Remote attackers with administrator privileges can access the user settings page to retrieve plaintext passwords.
0
Attacker Value
Unknown
CVE-2024-11981
Disclosure Date: November 29, 2024 (last updated December 21, 2024)
Certain models of routers from Billion Electric has an Authentication Bypass vulnerability, allowing unautheticated attackers to retrive contents of arbitrary web pages.
0
Attacker Value
Unknown
CVE-2024-11980
Disclosure Date: November 29, 2024 (last updated December 21, 2024)
Certain modes of routers from Billion Electric have a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly access the specific functionality to obtain partial device information, modify the WiFi SSID, and restart the device.
0
Attacker Value
Unknown
CVE-2024-28850
Disclosure Date: March 25, 2024 (last updated January 05, 2025)
WP Crontrol controls the cron events on WordPress websites. WP Crontrol includes a feature that allows administrative users to create events in the WP-Cron system that store and execute PHP code subject to the restrictive security permissions documented here. While there is no known vulnerability in this feature on its own, there exists potential for this feature to be vulnerable to RCE if it were specifically targeted via vulnerability chaining that exploited a separate SQLi (or similar) vulnerability. This is exploitable on a site if one of the below preconditions are met, the site is vulnerable to a writeable SQLi vulnerability in any plugin, theme, or WordPress core, the site's database is compromised at the hosting level, the site is vulnerable to a method of updating arbitrary options in the wp_options table, or the site is vulnerable to a method of triggering an arbitrary action, filter, or function with control of the parameters. As a hardening measure, WP Crontrol version 1…
0
Attacker Value
Unknown
CVE-2019-14918
Disclosure Date: January 09, 2020 (last updated February 21, 2025)
XSS in the DHCP lease-status table in Billion Smart Energy Router SG600R2 Firmware v3.02.rc6 allows an attacker to inject arbitrary HTML/JavaScript code to achieve client-side code execution via crafted DHCP request packets to etc_ro/web/internet/dhcpcliinfo.asp.
0
Attacker Value
Unknown
CVE-2019-14919
Disclosure Date: January 09, 2020 (last updated February 21, 2025)
An exposed Telnet Service on the Billion Smart Energy Router SG600R2 with firmware v3.02.rc6 allows a local network attacker to authenticate via hardcoded credentials into a shell, gaining root execution privileges over the device.
0
Attacker Value
Unknown
CVE-2019-14920
Disclosure Date: January 09, 2020 (last updated November 27, 2024)
Billion Smart Energy Router SG600R2 Firmware v3.02.rc6 allows an authenticated attacker to gain root execution privileges over the device via a hidden etc_ro/web/adm/system_command.asp shell feature.
0
Attacker Value
Unknown
CVE-2017-18368
Disclosure Date: May 02, 2019 (last updated January 23, 2025)
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.
0