Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2024-7029
Disclosure Date: August 02, 2024 (last updated September 18, 2024)
Commands can be injected over the network and executed without authentication.
1
Attacker Value
Unknown
CVE-2023-25437
Disclosure Date: April 27, 2023 (last updated October 08, 2023)
An issue was discovered in vTech VCS754 version 1.1.1.A before 1.1.1.H, allows attackers to gain escalated privileges and gain sensitive information due to cleartext passwords passed in the raw HTML.
0
Attacker Value
Unknown
CVE-2013-4982
Disclosure Date: December 27, 2019 (last updated November 27, 2024)
AVTECH AVN801 DVR has a security bypass via the administration login captcha
0
Attacker Value
Unknown
CVE-2019-13379
Disclosure Date: July 07, 2019 (last updated November 27, 2024)
On AVTECH Room Alert 3E devices before 2.2.5, an attacker with access to the device's web interface may escalate privileges from an unauthenticated user to administrator by performing a cmd.cgi?action=ResetDefaults&src=RA reset and using the default credentials to get in.
0
Attacker Value
Unknown
CVE-2018-16618
Disclosure Date: June 19, 2019 (last updated November 27, 2024)
VTech Storio Max before 56.D3JM6 allows remote command execution via shell metacharacters in an Android activity name. It exposes the storeintenttranslate.x service on port 1668 listening for requests on localhost. Requests submitted to this service are checked for a string of random characters followed by the name of an Android activity to start. Activities are started by inserting their name into a string that is executed in a shell command. By inserting metacharacters this can be exploited to run arbitrary commands as root. The requests also match those of the HTTP protocol and can be triggered on any web page rendered on the device by requesting resources stored at an http://127.0.0.1:1668/ URI, as demonstrated by the http://127.0.0.1:1668/dacdb70556479813fab2d92896596eef?';{ping,example.org}' URL.
0
Attacker Value
Unknown
CVE-2013-4980
Disclosure Date: March 03, 2014 (last updated October 05, 2023)
Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via a long string in the URI in an RTSP SETUP request.
0
Attacker Value
Unknown
CVE-2013-4981
Disclosure Date: March 03, 2014 (last updated October 05, 2023)
Buffer overflow in cgi-bin/user/Config.cgi in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via a long string in the Network.SMTP.Receivers parameter.
0
Attacker Value
Unknown
CVE-2008-3939
Disclosure Date: September 05, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the web interface in AVTECH PageR Enterprise before 5.0.7 allows remote attackers to read arbitrary files via directory traversal sequences in the URI.
0