Show filters
15 Total Results
Displaying 1-10 of 15
Sort by:
Attacker Value
Unknown

CVE-2023-42495

Disclosure Date: December 13, 2023 (last updated February 25, 2025)
Dasan Networks - W-Web versions 1.22-1.27 - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Attacker Value
Unknown

CVE-2014-8356

Disclosure Date: November 21, 2019 (last updated November 27, 2024)
The web administrative portal in Zhone zNID 2426A before S3.0.501 allows remote authenticated users to bypass intended access restrictions via a modified server response, related to an insecure direct object reference.
Attacker Value
Unknown

CVE-2019-10677

Disclosure Date: September 05, 2019 (last updated November 27, 2024)
Multiple Cross-Site Scripting (XSS) issues in the web interface on DASAN Zhone ZNID GPON 2426A EU version S3.1.285 devices allow a remote attacker to execute arbitrary JavaScript via manipulation of an unsanitized GET parameter: /zhndnsdisplay.cmd (name), /wlsecrefresh.wl (wlWscCfgMethod, wl_wsc_reg).
0
Attacker Value
Unknown

CVE-2019-9975

Disclosure Date: April 11, 2019 (last updated November 27, 2024)
DASAN H660RM devices with firmware 1.03-0022 use a hard-coded key for logs encryption. Data stored using this key can be decrypted by anyone able to access this key.
0
Attacker Value
Unknown

CVE-2019-9974

Disclosure Date: April 11, 2019 (last updated November 27, 2024)
diag_tool.cgi on DASAN H660RM GPON routers with firmware 1.03-0022 lacks any authorization check, which allows remote attackers to run a ping command via a GET request to enumerate LAN devices or crash the router with a DoS attack.
0
Attacker Value
Unknown

CVE-2019-9976

Disclosure Date: April 11, 2019 (last updated November 27, 2024)
The Boa server configuration on DASAN H660RM devices with firmware 1.03-0022 logs POST data to the /tmp/boa-temp file, which allows logged-in users to read the credentials of administration web interface users.
0
Attacker Value
Unknown

CVE-2019-8950

Disclosure Date: February 20, 2019 (last updated November 27, 2024)
The backdoor account dnsekakf2$$ in /bin/login on DASAN H665 devices with firmware 1.46p1-0028 allows an attacker to login to the admin account via TELNET.
0
Attacker Value
Unknown

CVE-2018-17868

Disclosure Date: October 01, 2018 (last updated November 27, 2024)
DASAN H660GW devices have Stored XSS in the Port Forwarding functionality.
0
Attacker Value
Unknown

CVE-2018-17867

Disclosure Date: October 01, 2018 (last updated November 27, 2024)
The Port Forwarding functionality on DASAN H660GW devices allows remote attackers to execute arbitrary code via shell metacharacters in the cgi-bin/adv_nat_virsvr.asp Addr parameter (aka the Local IP Address field).
0
Attacker Value
Unknown

CVE-2018-17869

Disclosure Date: October 01, 2018 (last updated November 27, 2024)
DASAN H660GW devices do not implement any CSRF protection mechanism.
0