Show filters
43 Total Results
Displaying 1-10 of 43
Sort by:
Attacker Value
Unknown

CVE-2024-23618

Disclosure Date: January 26, 2024 (last updated February 01, 2024)
An arbitrary code execution vulnerability exists in Arris SURFboard SGB6950AC2 devices. An unauthenticated attacker can exploit this vulnerability to achieve code execution as root.
Attacker Value
Unknown

CVE-2023-45992

Disclosure Date: October 19, 2023 (last updated January 13, 2024)
A vulnerability in the web-based interface of the RUCKUS Cloudpath product on version 5.12 build 5538 or before to could allow a remote, unauthenticated attacker to execute persistent XSS and CSRF attacks against a user of the admin management interface. A successful attack, combined with a certain admin activity, could allow the attacker to gain full admin privileges on the exploited system.
Attacker Value
Unknown

CVE-2023-27572

Disclosure Date: April 15, 2023 (last updated October 08, 2023)
An issue was discovered in CommScope Arris DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. A reflected XSS vulnerability was discovered in the https_redirect.php web page via the page parameter.
Attacker Value
Unknown

CVE-2023-27571

Disclosure Date: April 15, 2023 (last updated October 08, 2023)
An issue was discovered in DG3450 Cable Gateway AR01.02.056.18_041520_711.NCS.10. The troubleshooting_logs_download.php log file download functionality does not check the session cookie. Thus, an attacker can download all log files.
Attacker Value
Unknown

CVE-2022-45701

Disclosure Date: February 17, 2023 (last updated October 08, 2023)
Arris TG2482A firmware through 9.1.103GEM9 allow Remote Code Execution (RCE) via the ping utility feature.
Attacker Value
Unknown

CVE-2022-27002

Disclosure Date: March 15, 2022 (last updated November 08, 2023)
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the ddns function via the ddns_name, ddns_pwd, h_ddns、ddns_host parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Attacker Value
Unknown

CVE-2022-27001

Disclosure Date: March 15, 2022 (last updated October 07, 2023)
Arris TR3300 v1.0.13 were discovered to contain a command injection vulnerability in the dhcp function via the hostname parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Attacker Value
Unknown

CVE-2022-27000

Disclosure Date: March 15, 2022 (last updated October 07, 2023)
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the time and time zone function via the h_primary_ntp_server, h_backup_ntp_server, and h_time_zone parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Attacker Value
Unknown

CVE-2022-26999

Disclosure Date: March 15, 2022 (last updated October 07, 2023)
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the static ip settings function via the wan_ip_stat, wan_mask_stat, wan_gw_stat, and wan_dns1_stat parameters. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
Attacker Value
Unknown

CVE-2022-26998

Disclosure Date: March 15, 2022 (last updated October 07, 2023)
Arris TR3300 v1.0.13 was discovered to contain a command injection vulnerability in the wps setting function via the wps_enrolee_pin parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.