Show filters
10 Total Results
Displaying 1-10 of 10
Sort by:
Attacker Value
Unknown

CVE-2021-36489

Disclosure Date: February 03, 2023 (last updated October 08, 2023)
Buffer Overflow vulnerability in Allegro through 5.2.6 allows attackers to cause a denial of service via crafted PCX/TGA/BMP files to allegro_image addon.
Attacker Value
Unknown

CVE-2020-29292

Disclosure Date: December 30, 2021 (last updated February 23, 2025)
iBall WRD12EN 1.0.0 devices allow cross-site request forgery (CSRF) attacks as demonstrated by enabling DNS settings or modifying the range for IP addresses.
Attacker Value
Unknown

CVE-2020-15043

Disclosure Date: June 29, 2020 (last updated February 21, 2025)
iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP addresses.
Attacker Value
Unknown

CVE-2018-20008

Disclosure Date: May 28, 2019 (last updated November 27, 2024)
iBall Baton iB-WRB302N20122017 devices have improper access control over the UART interface, allowing physical attackers to discover Wi-Fi credentials (plain text) and the web-console password (base64) via the debugging console.
Attacker Value
Unknown

CVE-2018-6355

Disclosure Date: January 30, 2018 (last updated November 26, 2024)
/goform/setLang on iBall 300M devices with "iB-WRB302N_1.0.1-Sep 8 2017" firmware has Unauthenticated Stored Cross Site Scripting via the lang parameter.
0
Attacker Value
Unknown

CVE-2018-6388

Disclosure Date: January 29, 2018 (last updated November 26, 2024)
iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping test arguments on the Diagnostics page.
0
Attacker Value
Unknown

CVE-2018-6387

Disclosure Date: January 29, 2018 (last updated November 26, 2024)
iBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices have a hardcoded password of admin for the admin account, a hardcoded password of support for the support account, and a hardcoded password of user for the user account.
0
Attacker Value
Unknown

CVE-2017-11169

Disclosure Date: November 13, 2017 (last updated February 15, 2024)
Privilege Escalation on iBall iB-WRA300N3GT iB-WRA300N3GT_1.1.1 devices allows remote authenticated users to obtain root privileges by leveraging a guest/user/normal account to submit a modified privilege parameter to /form2userconfig.cgi.
0
Attacker Value
Unknown

CVE-2017-14244

Disclosure Date: September 17, 2017 (last updated November 26, 2024)
An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access administrative router settings by crafting URLs with a .cgi extension, as demonstrated by /info.cgi and /password.cgi.
Attacker Value
Unknown

CVE-2017-6558

Disclosure Date: March 09, 2017 (last updated November 26, 2024)
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the password.cgi file.
0